Soru

Zorluk: ZorSocial Engineering and Threat Types

A systems administrator at a healthcare facility is investigating a security incident in the radiology department. Several workstations have lost access to local and network files, which now display a .locked file extension alongside a text file demanding cryptocurrency payment within 48 hours. During the initial investigation, the technician learns that an unidentified individual left several unlabeled USB flash drives labeled 'Q3 Executive Bonuses' in the staff lounge, which multiple employees plugged into their workstations. Which of the following threat types and attack vectors are demonstrated in this scenario? (Select TWO.)

  1. RansomwareCevap
  2. BaitingCevap
  3. C
    Spear phishing
  4. D
    Keylogger
  5. E
    Shoulder surfing

Cevap

The threat types demonstrated in this scenario are Ransomware and Baiting.
Ransomware is demonstrated by the unauthorized encryption of user files coupled with a demand for cryptocurrency to restore access. Baiting is demonstrated by leaving malicious USB drives in a common work area with enticing labels to trick employees into introducing malware into the corporate environment.

Adım Adım Çözüm

1
Analyze the malicious payload and symptoms described in the scenario.
The renaming of files with a .locked extension and the presence of a cryptocurrency extortion note confirms a file-encrypting malware attack.
Ransomware specifically targets data availability by encrypting files and demanding ransom for decryption.
2
Analyze the social engineering attack vector used to deliver the payload.
Leaving physical USB flash drives labeled enticingly ('Q3 Executive Bonuses') in a common employee area exploits curiosity to compromise systems.
Baiting uses physical media pre-loaded with malware placed strategically to trick users into connecting them to internal network devices.

Anahtar Kavram

Social Engineering Vectors (Baiting) and Malware Classifications (Ransomware)
Tahmini Süre:2m 0s
Bu soruyu puanla