Soru

Zorluk: ZorSocial Engineering and Threat Types

A corporate IT technician is reviewing several recent security incident logs and employee reports across different departments. Match each security incident scenario on the left with its corresponding social engineering or threat classification on the right.

  • A targeted email sent specifically to the Chief Financial Officer containing personalized information to trick them into approving an urgent wire transfer.Whaling
  • An attacker compromises a niche industry news portal regularly visited by the company's software engineers to quietly infect their systems with malware.Watering hole attack
  • A fake company-wide alert email claiming a severe zero-day vulnerability exists and instructing employees to manually delete a vital operating system file.Security hoax
  • Infected USB flash drives labeled 'Executive Compensation Review' left in the company breakroom to entice curious employees to plug them into workstation computers.Baiting

Cevap

The targeted email to the CFO matches Whaling; the compromised industry portal matches Watering hole attack; the fake alert urging deletion of system files matches Security hoax; and leaving labeled USB drives in the breakroom matches Baiting.
Each attack vector relies on distinct delivery mechanisms and victim targets. Whaling targets high-profile executives like the CFO. Watering hole attacks infect popular third-party sites used by target employees. Security hoaxes trick users into taking self-destructive actions via false alarms. Baiting uses physical objects like flash drives to entice user interaction.

Adım Adım Çözüm

1
Analyze the target and vector of the first scenario involving the CFO.
Identified high-level executive targeting for financial wire transfer fraud.
Whaling specifically describes phishing aimed at high-ranking executives (C-level officers).
2
Examine the compromised third-party news portal scenario.
Identified strategic web compromise of a site frequently visited by target staff.
Watering hole attacks infect trusted websites commonly frequented by a target group rather than attacking the company network directly.
3
Evaluate the fake security email instructing file deletion.
Identified psychological manipulation leading to intentional user self-harm.
Security hoaxes create false sense of urgency to trick users into harming their own systems.
4
Review the physical USB flash drive scenario in the breakroom.
Identified physical media baiting attempting to exploit curiosity.
Baiting involves leaving malware-laden physical media in accessible places to lure targets into connecting them.

Anahtar Kavram

Social Engineering Tactics and Threat Classifications
Bu soruyu puanla