Match each social engineering attack vector on the left with its corresponding operational incident scenario description on the right.
- TailgatingAn unauthorized individual closely follows an authorized employee through a badge-restricted entry door without scanning credentials.
- Watering Hole AttackEmployees visiting an external industry news portal are redirected or infected via malicious scripts compromised by an adversary.
- SmishingStaff members receive fraudulent mobile text messages urging them to tap a hyperlink and confirm emergency account details.
- Shoulder SurfingAn observer covertly watches an employee enter authentication credentials onto a laptop screen in a public venue.
Answer
Tailgating matches unbadged physical entry by following authorized personnel; Watering Hole Attack matches compromising a trusted, frequently visited website; Smishing matches deceptive SMS text messages containing malicious links; Shoulder Surfing matches direct visual observation of screens or keyboard inputs.
Each attack vector correctly maps to its distinct channel and method of execution: tailgating exploits physical access doors, watering hole attacks compromise frequented web destinations, smishing relies on mobile SMS delivery, and shoulder surfing uses line-of-sight observation.
Step-by-Step Solution
Key Concept
Social Engineering Attack Vectors and Methods