During a post-incident investigation, a security analyst discovers that an attacker executed a multi-channel campaign against an organization. First, remote administrators received text messages during a off-hours maintenance window directing them to a fake portal to re-authenticate their multi-factor credentials due to an urgent server outage. Second, the attacker telephoned the helpdesk, impersonated the Chief Information Security Officer, and pressured an technician into bypassing standard identity verification to reset a high-privilege account password immediately. Which of the following social engineering attack vectors and influence principles were demonstrated in this incident? (Select TWO)
- Smishing leveraging urgency to capture administrative credentialsAnswer
- Vishing leveraging authority to bypass helpdesk verification proceduresAnswer
- CWatering hole attack leveraging consensus to compromise internal portals
- DBaiting leveraging scarcity to install rogue remote access software
Answer
The attack involved smishing leveraging urgency to capture administrative credentials, and vishing leveraging authority to bypass helpdesk verification procedures.
The scenario describes two distinct communication channels: text messaging (SMS) to lure administrators into revealing credentials under time pressure (smishing combined with urgency), and voice phone calls impersonating executive leadership to force policy bypasses (vishing combined with authority).
Step-by-Step Solution
Key Concept
Identification of social engineering attack vectors (Smishing, Vishing) and psychological principles of influence (Urgency, Authority).
Estimated Time:2m 0s