Threats, Vulnerabilities, and Mitigations

490 questions

Question 481Question

An employee at a corporate office scans their access badge to open a secured entrance door. Immediately after, an unidentified individual without a badge walks inside right behind the employee before the door closes. Which of the following social engineering attacks is best demonstrated in this scenario?

Show answer & explanation

Answer: Tailgating

Answer

Tailgating
The scenario describes tailgating (also called piggybacking), which takes place when an unauthorized person gains physical entrance into a restricted area by closely following an authorized employee who opened the door.

Step-by-Step Solution

1
Analyze the entry method described in the scenario
An unauthorized individual gains access into a secured facility by following immediately behind an authenticated worker.
Identifying the method of access separates physical facility vectors from digital network attack vectors.
2
Match the behavior to standard social engineering attack definitions
Following an authorized person through a secure portal without credentials defines tailgating (or piggybacking).
Tailgating relies on human courtesy or social norms to bypass physical authentication barriers.

Key Concept

Tailgating physical social engineering attack
Estimated Time:45s
Question 482Question

An employee attempting to navigate to an external vendor portal mistypes the domain name in the web browser address bar and is redirected to a fraudulent site designed to mimic the authentic login screen. Which of the following attack vectors is demonstrated in this scenario?

Show answer & explanation

Answer: Typosquatting

Answer

Typosquatting
Typosquatting (also known as URL hijacking) occurs when threat actors register domain names that are slight misspellings of legitimate websites to capture traffic from users who make typographical errors.

Step-by-Step Solution

1
Identify the attack mechanism presented in the scenario.
The user mistyped a legitimate domain name in the browser address bar.
The attack relies on typographical mistakes made during web navigation.
2
Match the mechanism to the correct social engineering attack term.
Registering common misspellings of popular domains to trap users is known as typosquatting (or URL hijacking).
This directly aligns with the definition of typosquatting.

Key Concept

Typosquatting (URL Hijacking)
Question 483Question

Match each social engineering principle of influence on the left with its corresponding enterprise attack scenario description on the right.

Click a left item, then click its matching right item

Items

Authority
Consensus
Scarcity
Urgency

Matches

Show answer & explanation

Answer

Authority matches the executive impersonation scenario; Consensus matches the claim that all other department heads submitted credentials; Scarcity matches the claim of limited remaining license slots; Urgency matches the claim of an imminent server crash within minutes.
Each principle of influence aligns with its specific psychological trigger: Authority uses hierarchy and position, Consensus relies on peer participation, Scarcity uses perceived limited availability, and Urgency creates artificial time pressure.

Step-by-Step Solution

1
Analyze each scenario on the right to identify the psychological driver leveraged by the attacker.
The executive role exploits power (Authority); peer actions exploit social proof (Consensus); limited licenses exploit limited supply (Scarcity); short deadlines exploit time pressure (Urgency).
Social engineering attacks rely on specific psychological principles of influence to manipulate victims.
2
Pair each principle of influence on the left to its corresponding attack scenario.
Authority maps to executive demand, Consensus maps to peer compliance, Scarcity maps to limited slots, and Urgency maps to the tight time constraint.
Matching principles to their defining characteristics confirms correct identification of attack vectors.

Key Concept

Principles of Influence in Social Engineering
Estimated Time:1m 0s
Question 484Question

An organization's security team detects an unauthorized login to a corporate account. Incident analysis reveals that the compromised employee received an SMS notification on their mobile device claiming to be from the IT helpdesk, warning that their account access would be revoked unless verified immediately via a provided URL. The link directed the user to a fraudulent authentication portal where their credentials were captured. Which social engineering attack vector initiated this security incident?

Show answer & explanation

Answer: Smishing

Answer

Smishing is the social engineering attack vector delivered through SMS text messaging.
Smishing (SMS phishing) specifically leverages Short Message Service (SMS) text messages as the vector to deliver deceptive lures and malicious links to mobile devices. In this scenario, the attack was initiated through an urgent SMS notification containing a link to a credential harvesting site.

Step-by-Step Solution

1
Identify the communication channel used in the attack vector.
The attack initiated with an SMS text message delivered to a mobile device.
Social engineering attack classification relies on the transport medium utilized to contact the target.
2
Map the identified SMS channel to the correct Security+ attack taxonomy term.
Phishing conducted specifically over SMS text messages is defined as smishing.
Differentiation between phishing variants depends on the transport protocol (SMS = smishing, voice call = vishing, targeted email = spear phishing).

Key Concept

Social Engineering Attack Vectors and Transport Media
Estimated Time:1m 0s
Question 485Question

A field technician working at a remote facility discovers several corporate-branded USB flash drives left on tables in the facility's cafeteria. Each drive is labeled with the text "Q3 Executive Compensation & Bonus Allocations - Confidential." Driven by curiosity, the technician plugs one of the drives into a corporate network workstation to view the contents, triggering an automatic payload execution that harvests local account credentials. Which type of social engineering attack vector did the threat actor utilize in this scenario?

Show answer & explanation

Answer: Baiting

Answer

Baiting is the social engineering vector utilized when an attacker leaves infected physical media in accessible locations, exploiting human curiosity to induce victims to insert the media into target systems.
Baiting involves leaving a malware-infected physical device (such as a USB drive) in a location where target users are likely to find it. The attacker relies on victim curiosity (heightened by enticing labels like confidential financial documents) to prompt them to connect the device to an enterprise computer.

Step-by-Step Solution

1
Analyze the attack medium and delivery mechanism described in the scenario.
The attack relies on physical media (labeled USB flash drives) intentionally placed in a public/accessible employee area.
Identifying the medium (physical storage device vs. web browser vs. physical door) narrows down the social engineering category.
2
Evaluate the psychological psychological trigger exploited by the threat actor.
The label 'Q3 Executive Compensation' appeals directly to employee curiosity and greed.
Social engineering tactics manipulate specific human psychological factors; curiosity piqued by high-value labeled media is characteristic of baiting.
3
Match the attack indicators to the specific CompTIA Security+ social engineering taxonomy definition.
Leaving malicious hardware media for an unsuspecting victim to find and insert into a workstation defines a baiting attack.
Distinguishing baiting from watering hole or pretexting ensures accurate vector identification.

Key Concept

Baiting Attack Vector
Estimated Time:1m 0s
Question 486Question

A receptionist at an enterprise regional office receives a phone call from an individual claiming to be a technician from the building management company. The caller states that an urgent HVAC emergency requires immediate physical access to the server room key box and asks the receptionist to read the emergency access PIN code over the phone. The caller provides fake ticket numbers and references real facility manager names to build credibility. Which of the following social engineering techniques did the attacker primarily execute in this scenario?

Show answer & explanation

Answer: Pretexting

Answer

Pretexting
Pretexting is the act of creating a believable fabricated scenario or identity (the pretext) to trick a victim into disclosing sensitive information or granting unauthorized access. In this scenario, the attacker impersonated a facilities technician and fabricated an HVAC emergency to deceive the receptionist into revealing a sensitive PIN.

Step-by-Step Solution

1
Analyze the attack vector and communication channel in the scenario.
The attack uses direct phone communication where the adversary impersonates an authorized technician and provides fabricated context (fake ticket numbers, real employee names).
Identifying the method of contact helps narrow down the social engineering classification.
2
Evaluate the underlying psychological tactic.
The attacker creates a false background story (an emergency HVAC maintenance event) to manipulate the recipient into breaking security protocols.
Creating a fake background narrative to establish trust and trick a target is the defining characteristic of pretexting.
3
Compare the scenario against alternative social engineering definitions.
Watering hole attacks involve site compromise, baiting uses tangible enticements, and pharming uses DNS manipulation; none of these rely on direct verbal narrative fabrication.
Differentiating techniques ensures accurate categorization based on attack mechanics.

Key Concept

Pretexting in Social Engineering
Question 487Question

Match each social engineering attack vector or influence principle on the left with the enterprise incident scenario on the right that best demonstrates its execution.

Click a left item, then click its matching right item

Items

Whaling
Shoulder Surfing
Diversion Theft
Scarcity (Influence Principle)

Matches

Show answer & explanation

Answer

Whaling pairs with the scenario involving a targeted email sent directly to the CEO. Shoulder Surfing pairs with the scenario involving direct visual observation of credential entry in a cafe. Diversion Theft pairs with the scenario involving redirecting incoming physical shipments of equipment. Scarcity pairs with the scenario leveraging limited remaining trial licenses to trick staff.
Each attack vector or principle matches its operational execution: Whaling targets top executives (CEO), Shoulder Surfing relies on direct visual observation, Diversion Theft intercepts physical transit shipments, and Scarcity exploits psychological urgency built around limited remaining quantities.

Step-by-Step Solution

1
Identify the target profile for Whaling
Recognize that Whaling specifically targets high-ranking executives like C-level leadership, matching the CEO wire transfer scenario.
Whaling is a specialized variant of spear phishing aimed at high-value targets within an organization.
2
Analyze physical observation threat vectors
Identify Shoulder Surfing as the technique where an attacker visually eavesdrops on password or credential entry in public spaces.
Direct visual observation of keyboards and screens falls directly under shoulder surfing risks.
3
Evaluate supply chain physical transport attack methods
Link Diversion Theft to the physical rerouting of incoming hardware packages and logistics couriers.
Diversion theft focuses on intercepting goods in transit by deceiving transportation personnel.
4
Evaluate psychological principles of influence
Associate Scarcity with the tactic of offering limited availability items (such as only five trial licenses) to coerce hasty victim action.
Scarcity relies on the fear of missing out due to restricted availability or strict deadlines.

Key Concept

Social Engineering Vectors and Principles of Influence
Estimated Time:1m 30s
Question 488Question

An accounts payable specialist receives an urgent email that appears to originate from the organization's Chief Financial Officer (CFO). The message references an undisclosed legal settlement and directs the specialist to immediately wire $45,000 to an external account, explicitly instructing them to bypass normal dual-authorization procedures to meet a strict deadline. Investigation reveals the message originated from an external domain registered to mimic the enterprise domain by substituting the letter 'o' with the number '0'. Which of the following attack types is best described in this scenario?

Show answer & explanation

Answer: Whaling combined with typosquatting

Answer

Whaling combined with typosquatting
Whaling is a specialized form of spear phishing that specifically targets or impersonates senior executives (such as a CFO) to authorize high-value transactions or release sensitive data. Typosquatting (also known as URL hijacking) involves registering domain names that closely resemble legitimate domains (such as replacing the letter 'o' with the digit '0') to deceive recipients into believing the sender is authentic.

Step-by-Step Solution

1
Analyze the target and impersonation role in the scenario
The attack impersonates high-level corporate leadership (CFO) to mandate financial transactions, which characterizes a whaling attack variant of spear phishing.
Whaling focuses on executive leadership roles or high-value targets.
2
Analyze the technical vector used to deceive the recipient
The attacker registered a fraudulent domain using character substitution ('0' for 'o') to trick users looking at sender addresses.
Typosquatting relies on subtle typographical variations of legitimate domain names.
3
Synthesize the attack elements to select the correct social engineering combination
The combination of executive impersonation (whaling) and deceptive domain registration (typosquatting) matches the scenario.
Both techniques work together to establish authority and bypass casual human verification.

Key Concept

Executive Impersonation (Whaling) and Deceptive Domain Registration (Typosquatting)
Question 489Question

An organization's security operations center (SOC) detects an incident where an employee received a text message on their mobile phone containing an urgent link to verify their corporate single sign-on (SSO) credentials on a fraudulent domain. Shortly after, an unknown attacker calls the IT helpdesk, posing as the employee and using previously gathered personal details to request an account recovery passcode. Which of the following social engineering vectors were directly utilized in this attack scenario? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Smishing; Vishing

Answer

The attack scenario directly utilized smishing and vishing.
Smishing and vishing are correct because the attacker used SMS text messages containing malicious links and telephone calls impersonating an employee to execute the credential harvesting and unauthorized access attempt.

Step-by-Step Solution

1
Analyze the SMS message vector
Identified smishing due to fraudulent text messages sent to mobile devices.
Phishing delivered via short message service (SMS) is categorized specifically as smishing.
2
Analyze the phone call and impersonation vector
Identified vishing due to deceptive telephone interaction targeting the helpdesk.
Voice-based social engineering attempts conducted over the phone constitute vishing.

Key Concept

Social Engineering Attacks and Vectors
Question 490Question

During a routine audit, an incident response team discovers that multiple remote employees entered their domain credentials into a web page that visually duplicated the organization's authentic single sign-on (SSO) portal. Investigation reveals that the domain name used in the attack was registered by an external third party and contained a single transposed letter relative to the official enterprise URL. Which social engineering attack vector was directly executed in this scenario?

Show answer & explanation

Answer: Typosquatting

Answer

Typosquatting is the correct vector, as it explicitly relies on registering slight misspellings or character transpositions of legitimate domain names to trick users into visiting deceptive websites.
Typosquatting (also known as URL hijacking) occurs when an attacker registers domain names that are slight misspellings, character swaps, or variations of a legitimate domain. When users inadvertently type the wrong address or follow a link to the spoofed domain, they are presented with a fraudulent site designed to harvest sensitive information such as SSO credentials.

Step-by-Step Solution

1
Analyze the scenario indicators
The attacker registered a look-alike domain with a transposed letter pointing to a cloned SSO landing page.
Identifying the specific mechanism used by the attacker establishes the underlying social engineering category.
2
Compare against social engineering definitions
Registering URLs that mirror legitimate corporate domains via misspellings/transpositions matches the exact definition of typosquatting (URL hijacking).
Differentiating between delivery mechanisms (email vs. phone vs. fake domain registration) ensures correct vector classification.

Key Concept

Typosquatting (URL Hijacking)
PreviousPage 25 / 25
Threats, Vulnerabilities, and Mitigations Practice Questions — CompTIA Security+ — Page 25 | Examkin