Question

Difficulty: Very hardSocial Engineering Attacks and Vectors

An enterprise security operations center is reviewing four complex, multi-stage security incidents involving targeted human manipulation. Match each social engineering tactical delivery technique on the left to the corresponding operational scenario indicator on the right.

  • Reverse Social EngineeringAn adversary intentionally causes localized network disruptions after placing fraudulent IT support flyers in a breakroom, causing impacted personnel to voluntarily call a caller-controlled helpline for technical assistance.
  • MFA Fatigue (Push Spamming) with VishingAn attacker generates dozens of repeated secondary authentication prompts outside business hours while posing over a phone call as an urgent helpdesk technician resolving an account lock out.
  • Watering Hole AttackAn attacker compromises a niche vendor technical forum regularly visited by company engineers, embedding zero-day exploit payloads into downloadable documentation files.
  • Pretexting with TyposquattingAn adversary registers a visually identical domain to a key supplier and impersonates their chief financial officer via tailored email correspondence to request updated routing numbers for pending invoices.

Answer

Reverse Social Engineering matches the scenario where an adversary causes network disruptions and advertises a fake helpline so victims call them. MFA Fatigue with Vishing matches the scenario involving repeated push notification prompts coupled with an urgent phone call from a fake technician. Watering Hole Attack matches the scenario where a niche vendor technical forum frequented by engineers is compromised. Pretexting with Typosquatting matches the scenario where a lookalike supplier domain and false narrative are used to modify invoice payment details.
Each attack vector is correctly paired based on operational mechanics: Reverse Social Engineering relies on victim-initiated contact; MFA Fatigue combined with Vishing leverages pushed authentication spam alongside voice coercion; Watering Hole attacks exploit trusted industry watering holes/websites; and Pretexting with Typosquatting combines fraudulent role-play with misleading lookalike domains.

Step-by-Step Solution

1
Analyze the tactical delivery methods
Identify key characteristics of Reverse Social Engineering, MFA Fatigue/Vishing, Watering Hole, and Pretexting with Typosquatting.
Matching requires identifying the core delivery vector and psychological levers used in each attack.
2
Evaluate the first scenario involving breakroom flyers and self-initiated victim calls
Map to Reverse Social Engineering.
In reverse social engineering, the target relies on assistance published by the attacker, initiating the contact themselves.
3
Evaluate the second scenario involving compromised niche vendor forums
Map to Watering Hole Attack.
Watering hole attacks selectively infect websites known to be trusted and frequented by the target demographic.
4
Evaluate the third scenario involving off-hours push prompts and phone calls
Map to MFA Fatigue with Vishing.
Push spamming weakens user resistance through repetitive MFA prompts, while voice phishing reinforces the false urgency.
5
Evaluate the fourth scenario involving lookalike vendor domains and executive impersonation
Map to Pretexting with Typosquatting.
Typosquatting provides technical plausibility via lookalike domains, while pretexting builds the false narrative to redirect funds.

Key Concept

Social Engineering Attack Vectors and Incident Indicators
Rate this question