An enterprise security operations center is reviewing four complex, multi-stage security incidents involving targeted human manipulation. Match each social engineering tactical delivery technique on the left to the corresponding operational scenario indicator on the right.
- Reverse Social EngineeringAn adversary intentionally causes localized network disruptions after placing fraudulent IT support flyers in a breakroom, causing impacted personnel to voluntarily call a caller-controlled helpline for technical assistance.
- MFA Fatigue (Push Spamming) with VishingAn attacker generates dozens of repeated secondary authentication prompts outside business hours while posing over a phone call as an urgent helpdesk technician resolving an account lock out.
- Watering Hole AttackAn attacker compromises a niche vendor technical forum regularly visited by company engineers, embedding zero-day exploit payloads into downloadable documentation files.
- Pretexting with TyposquattingAn adversary registers a visually identical domain to a key supplier and impersonates their chief financial officer via tailored email correspondence to request updated routing numbers for pending invoices.
Answer
Reverse Social Engineering matches the scenario where an adversary causes network disruptions and advertises a fake helpline so victims call them. MFA Fatigue with Vishing matches the scenario involving repeated push notification prompts coupled with an urgent phone call from a fake technician. Watering Hole Attack matches the scenario where a niche vendor technical forum frequented by engineers is compromised. Pretexting with Typosquatting matches the scenario where a lookalike supplier domain and false narrative are used to modify invoice payment details.
Each attack vector is correctly paired based on operational mechanics: Reverse Social Engineering relies on victim-initiated contact; MFA Fatigue combined with Vishing leverages pushed authentication spam alongside voice coercion; Watering Hole attacks exploit trusted industry watering holes/websites; and Pretexting with Typosquatting combines fraudulent role-play with misleading lookalike domains.
Step-by-Step Solution
Key Concept
Social Engineering Attack Vectors and Incident Indicators