Soru

Zorluk: OrtaSocial Engineering and Threat Types

Match each social engineering threat type on the left with its corresponding attack methodology on the right.

  • Spear PhishingA targeted email attack customized specifically to a single high-value individual or organization using gathered background information.
  • Watering Hole AttackInfecting a specific third-party website frequently visited by employees of a target organization to compromise their devices.
  • PretextingCreating a fake scenario or persona to manipulate a target into revealing confidential credentials or private information.
  • Shoulder SurfingDirectly observing a user's display screen or keyboard entry in a public or open workplace to steal sensitive data.

Cevap

Spear Phishing matches with targeted, customized email communications; Watering Hole Attack matches with compromising frequently visited third-party websites; Pretexting matches with inventing a fabricated scenario to build trust; Shoulder Surfing matches with direct visual observation of screens or keyboards.
Each threat type is paired precisely with its defined attack vector: Spear phishing utilizes highly customized emails aimed at specific individuals, watering hole attacks infect websites frequently accessed by target groups, pretexting relies on fabricated scenarios to extract credentials, and shoulder surfing physically observes screens or keypads.

Adım Adım Çözüm

1
Analyze digital versus physical social engineering attack vectors
Identified direct visual observation as shoulder surfing and customized email targeting as spear phishing.
Categorizing the operational vector isolates the specific threat definition.
2
Distinguish between strategic web compromises and identity fabrication scenarios
Watering hole attack targets shared web resources, whereas pretexting relies on impersonation and narrative creation.
Understanding the delivery mechanism differentiates watering hole attacks from pretexting scenarios.
3
Map each threat term to its exact operational description
All four threat pairs correctly aligned based on CompTIA threat taxonomy definitions.
Ensures accurate identification for security incident diagnosis and mitigation.

Anahtar Kavram

Social Engineering Threat Methodologies and Classifications
Bu soruyu puanla