Soru

Zorluk: OrtaSocial Engineering and Threat Types

A human resources administrator receives a targeted email appearing to come from the company's payroll software vendor, requesting an urgent update to employee direct deposit banking details via an attached link. On the same day, an IT technician discovers several unlabelled USB flash drives intentionally left on tables in the employee cafeteria. Which of the following social engineering tactics are demonstrated in these security incidents? (Select TWO.)

  1. Spear phishingCevap
  2. BaitingCevap
  3. C
    Tailgating
  4. D
    Vishing
  5. E
    Ransomware

Cevap

The correct tactics are spear phishing and baiting.
Spear phishing describes a targeted digital attack aimed at specific personnel (such as HR administrator) to compromise sensitive corporate data. Baiting describes leaving physical storage media (such as USB drives) in public locations to lure curious individuals into connecting them to network workstations.

Adım Adım Çözüm

1
Analyze the fraudulent email incident directed at the HR administrator.
Determine that sending a targeted email to a specific role to compromise payroll credentials is an example of spear phishing.
Spear phishing targets specific individuals or departments using tailored information rather than generic mass distributions.
2
Analyze the physical USB flash drives discovered in the cafeteria.
Determine that leaving physical media in high-traffic common areas to entice victims into connecting them to company computers is baiting.
Baiting leverages human curiosity or greed by promising a physical or digital reward.

Anahtar Kavram

Identifying Social Engineering Attack Vectors (Spear Phishing and Baiting)
Bu soruyu puanla