Question

Difficulty: MediumSocial Engineering Attacks and Vectors

A corporate finance officer receives an urgent SMS message on their personal mobile phone claiming that a critical vendor invoice is past due and requiring immediate review via a provided shortened link. Upon clicking the link, the officer is directed to a login page and receives a follow-up call from an individual claiming to be a senior IT auditor. The caller uses authoritative technical terms and pressures the officer to disclose their multi-factor authentication (MFA) verification code to resolve an apparent account lock. Which of the following social engineering attack vectors and principles of influence were directly employed in this scenario? (Select TWO.)

  1. SmishingAnswer
  2. B
    Watering hole attack
  3. PretextingAnswer
  4. D
    Typosquatting

Answer

The attack involved Smishing (using SMS to deliver a phishing link) and Pretexting (fabricating an IT auditor identity to manipulate the employee into sharing MFA credentials).
Smishing is used because the initial social engineering attack vector was delivered via text message (SMS). Pretexting is present because the attacker created a fabricated persona and scenario (a senior IT auditor resolving an account lock) to trick the target into revealing sensitive MFA credentials over the phone.

Step-by-Step Solution

1
Analyze the initial delivery mechanism described in the scenario
The message was delivered via SMS text message requesting urgent action, which defines smishing.
Identifying the medium (SMS) categorizes the specific phishing variant.
2
Analyze the secondary voice communication and psychological tactic
The caller created a fake scenario as an authoritative IT auditor to obtain credentials, which defines pretexting.
Pretexting involves building a believable backstory and role to establish trust or convey authority to trick the target.

Key Concept

Social Engineering Attack Vectors and Influence Tactics
Estimated Time:1m 30s
Rate this question