A tier 2 IT support technician is reviewing an incident report from a regional office. A visitor wearing a high-visibility utility vest approached the front reception desk, presented a printed fake work order for emergency electrical maintenance, and convinced the receptionist to grant access to restricted communications closets without standard badge verification. Once inside, the intruder installed a rogue hardware keylogger on an unmonitored workstation. Which of the following social engineering techniques was primarily used to gain initial unauthorized physical entry to the facility?
- PretextingCevap
- BTailgating
- CSpear phishing
- DBaiting
Cevap
The correct threat classification is Pretexting.
Pretexting is the social engineering technique where an attacker crafts a fictitious story or scenario (the pretext), often adopting a persona such as a repair technician or auditor, to trick individuals into granting physical or logical access they should not have.
Adım Adım Çözüm
Anahtar Kavram
Pretexting in Social Engineering