Threats, Vulnerabilities, and Mitigations
490 questions
Match each social engineering attack vector on the left with its corresponding operational incident scenario description on the right.
Click a left item, then click its matching right item
Items
Matches
During a physical security assessment, security auditors observe an unauthorized individual entering a secured facility by following closely behind a credentialed staff member through a badge-access door. Once inside the facility, the individual secretly records an administrator entering sensitive credentials onto a workstation keyboard from a nearby seating area. Which of the following social engineering vectors were executed during this physical security breach? (Select TWO)
Select all that apply
An organization's finance clerk receives an urgent email appearing to originate from the Chief Executive Officer, requesting an immediate wire transfer to close a confidential vendor contract. Shortly after receiving the email, the clerk receives a phone call from an individual claiming to be the CEO, urging them to bypass standard dual-authorization procedures due to extreme time constraints. Subsequent investigation reveals the attacker created a false narrative and spoofed the internal caller ID.
Which of the following social engineering attack vectors and techniques are directly demonstrated in this scenario? (Select TWO).
Select all that apply
Match each social engineering incident scenario on the left with the specific social engineering attack vector utilized on the right.
Click a left item, then click its matching right item
Items
Matches
During a malware investigation, an incident responder discovers that several engineers in an organization had their workstations infected after visiting an authentic, third-party software development forum that they frequently use for work. The attacker had previously breached the forum and injected a malicious drive-by download script targeting visitors originating from the organization's corporate IP range. Which of the following social engineering attack vectors was executed by the threat actor?
A financial analyst receives an unexpected telephone call from an individual claiming to be a senior analyst from the corporate internal audit department. The caller states that an urgent financial discrepancy was flagged during an ongoing audit and directs the analyst to verbally confirm their network login credentials and multi-factor authentication code to verify their identity before the system is locked out. Which social engineering attack vector is demonstrated in this scenario?
Match each enterprise security incident scenario on the left with the specific social engineering attack vector utilized on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise security operations center (SOC) discovers that several employees mistakenly submitted their corporate domain credentials to an external login portal. The malicious portal was hosted on `login.acme-corp.net`, whereas the legitimate enterprise single sign-on (SSO) portal is `login.acme-corp.com`. The attacker registered the alternate top-level domain to impersonate the enterprise authentication interface. Which of the following social engineering attack vectors was primarily executed by the attacker?
A security analyst is reviewing incident reports from remote staff who experienced a coordinated social engineering campaign. Several employees received text messages on their corporate mobile devices containing links to a counterfeit login portal, while other employees received phone calls from an attacker posing as IT support attempting to obtain credential resets. Which of the following social engineering attack vectors were executed during this incident? (Select TWO.)
Select all that apply
An administrative assistant at a logistics firm receives an urgent text message on their corporate mobile phone from an unverified short code claiming to be the company's Vice President of Operations. The message asserts that a supplier invoice must be authorized immediately via a provided short link to prevent supply chain disruption, warning that delay will result in severe administrative penalty. Which social engineering attack vector and primary influence principle are demonstrated in this scenario?
Match each enterprise security incident scenario on the left with the corresponding social engineering attack vector or technique on the right.
Click a left item, then click its matching right item
Items
Matches
A security analyst is investigating a multi-vector social engineering campaign targeting an organization's accounting department. The incident report highlights two distinct activities: first, an attacker placed a direct phone call to a payroll clerk, posing as an executive and demanding an immediate wire transfer; second, several accountants received SMS text messages on their corporate mobile devices containing links to a fraudulent login page designed to harvest credentials. Which of the following social engineering attack vectors were executed during this campaign? (Select TWO.)
Select all that apply
An enterprise system administrator receives an unsolicited telephone call from an individual claiming to represent the organization's central data center team. The caller states that an emergency database synchronization failure is occurring and demands that the administrator immediately provide their two-factor authentication bypass code to prevent widespread data loss. Which social engineering attack vector is the caller primarily utilizing?
During a routine security audit, an incident handler observes that several software developers in a research division were redirected to a compromised third-party technical discussion forum they frequently visit. The compromised forum silently downloaded a malicious browser extension to harvest API tokens used in the company's continuous integration pipeline. Which of the following social engineering techniques best describes this initial access vector?
Match each social engineering attack vector to its corresponding real-world enterprise incident scenario.
Click a left item, then click its matching right item
Items
Matches
An attacker contacts a remote branch manager while posing as an executive auditor from corporate headquarters. The attacker presents a fabricated narrative regarding an urgent regulatory compliance audit and persuades the branch manager to bypass standard identity verification procedures to grant temporary network credentials. Which social engineering technique was primarily utilized by the attacker to manipulate the victim?
A security analyst is investigating a dual-vector social engineering campaign targeting a corporate facility. During the investigation, the analyst notes that employees received text messages prompting them to verify credentials on a spoofed portal, while physical USB flash drives labeled "Executive Salaries" were strategically dropped in the employee parking area. Which of the following social engineering attack vectors were executed during this campaign? (Select TWO.)
Select all that apply
An IT administrator receives an unverified request for sensitive internal network topology diagrams. When the administrator hesitates to comply, the requester claims that three senior network engineers in the department have already submitted their respective section diagrams for the ongoing audit. Reassured that colleagues have already complied, the administrator releases the requested files. Which of the following principles of influence did the attacker primarily exploit?
Match each social engineering attack vector on the left to the real-world enterprise incident scenario on the right that best illustrates it.
Click a left item, then click its matching right item
Items
Matches
An attacker registers a domain name that closely resembles an enterprise's official login portal by altering a single character in the domain URL. The attacker uses this fraudulent domain to host a spoofed site that captures employee credentials when users accidentally mistype the legitimate web address. Which of the following social engineering attack vectors is best illustrated in this scenario?