Soru

Zorluk: ZorSocial Engineering and Threat Types

A security technician at a defense contractor is investigating a multi-stage security incident reported across the corporate facility. Physical access logs and security footage show an unknown individual wearing a fake delivery uniform closely following an authorized employee through a badge-restricted turnstile without scanning an access card. Later that day, several senior lead engineers received customized emails containing authentic project reference numbers and names of their team members, requesting that they click an external link to verify their corporate credentials. Which of the following social engineering threat types were directly executed during this incident? (Select TWO.)

  1. TailgatingCevap
  2. Spear phishingCevap
  3. C
    Vishing
  4. D
    Dumpster diving
  5. E
    Shoulder surfing

Cevap

The attack involved Tailgating (unauthorized physical entry by following an employee) and Spear Phishing (highly customized email targeting specific engineers).
The scenario describes two distinct threat vectors: physical entry achieved by closely following an authorized badged user through a security turnstile (Tailgating), and an electronic attack utilizing customized internal project references sent to specific senior staff members to harvest credentials (Spear Phishing).

Adım Adım Çözüm

1
Analyze the physical access breach described in the scenario.
The intruder wearing a delivery uniform closely followed a badged employee through a restricted turnstile without presenting credentials.
This physical social engineering technique of entering restricted areas behind authorized personnel is defined as tailgating.
2
Analyze the digital attack vectors presented in the incident report.
Selected senior lead engineers received tailored emails with internal project names and coworker information designed to steal credentials.
Targeted, customized electronic messages directed at specific key individuals inside an organization represent spear phishing rather than broad phishing.
3
Differentiate and eliminate non-matching social engineering attack types.
Vishing requires phone interaction, dumpster diving requires searching trash receptacles, and shoulder surfing requires direct visual monitoring of screens.
None of these secondary vectors were indicated in the security footage or email log evidence.

Anahtar Kavram

Identifying Physical and Digital Social Engineering Vectors
Tahmini Süre:2m 0s
Bu soruyu puanla