Question

Difficulty: EasySocial Engineering Attacks and Vectors

An organization discovers that several employees received fraudulent text messages on their personal mobile devices claiming an urgent security update is required for their corporate email access, directing them to a credential-harvesting site. At the same time, an unauthorized individual attempted to enter the facility by closely following an authorized worker through a secure entrance. Which of the following social engineering vectors are demonstrated in these scenarios? (Select TWO.)

  1. SmishingAnswer
  2. TailgatingAnswer
  3. C
    Watering hole attack
  4. D
    Vishing

Answer

Smishing and Tailgating are the social engineering vectors demonstrated.
Smishing represents phishing delivered via SMS text messages on mobile devices to steal credentials. Tailgating is a physical social engineering tactic where an unauthorized actor follows an authorized person through a secured barrier without authentication.

Step-by-Step Solution

1
Analyze the mobile communication component
Identify that malicious text messaging (SMS) directing users to a fake site is smishing.
Smishing specifically leverages mobile text messaging channels to deliver phishing lures.
2
Analyze the physical access breach component
Identify that following an authorized employee through a secure doorway without credentials is physical tailgating.
Tailgating relies on social courtesy or distraction to gain unauthenticated entry into restricted physical spaces.

Key Concept

Social Engineering Attack Vectors (Smishing and Tailgating)
Rate this question