Soru

Zorluk: OrtaSocial Engineering and Threat Types

A technician is reviewing incident reports following a security breach at a branch office. According to the investigation, an attacker called several employees pretending to be internal IT support to solicit user credentials over the telephone. Later that afternoon, the attacker entered the restricted server facility without a badge by closely following a worker who held the door open out of courtesy. Which of the following social engineering threat types were directly demonstrated in this scenario? (Select TWO).

  1. VishingCevap
  2. PiggybackingCevap
  3. C
    Shoulder surfing
  4. D
    Dumpster diving
  5. E
    Watering hole attack

Cevap

The correct threat types demonstrated in the incident are vishing and piggybacking.
The scenario describes two distinct attacks: soliciting credentials over the phone (voice phishing or vishing) and gaining physical entry into a secure building by relying on an employee to hold the door open (piggybacking).

Adım Adım Çözüm

1
Analyze the phone-based attack vector described in the incident report.
Impersonating IT personnel over the telephone to solicit credentials matches the definition of voice phishing (vishing).
Vishing specifically relies on voice communications to conduct social engineering attacks.
2
Analyze the physical access vector described in the incident report.
Entering a physical security perimeter by having an authorized employee hold the door open constitutes piggybacking.
Piggybacking relies on social courtesy to gain access behind an authorized badge holder.

Anahtar Kavram

Identifying social engineering attack vectors across voice and physical channels
Bu soruyu puanla