An IT security technician is investigating a multi-stage security incident at a corporate facility. The investigation reveals that an attacker contacted a junior financial accountant via a phone call, posing as an internal IT service desk engineer to trick the accountant into verifying their credentials and approving an unauthorized multi-factor authentication (MFA) push notification. Additionally, physical security footage indicates that the attacker entered the restricted server room by closely following an authorized employee through a badge-protected security door before it latched. Which of the following social engineering threat types were executed during this incident? (Select TWO.)
- VishingCevap
- BWhaling
- TailgatingCevap
- DShoulder surfing
- EDumpster diving
Cevap
The social engineering threat types executed during the incident are Vishing and Tailgating.
Vishing and Tailgating are correct. Vishing is voice-based phishing where attackers use phone calls to manipulate victims into exposing sensitive access controls or MFA prompts. Tailgating is an unauthorized physical entry tactic where an attacker closely follows an authorized person into a secured building or room.
Adım Adım Çözüm
Anahtar Kavram
Identifying social engineering threat types based on digital communication vectors and physical security breaches.
Tahmini Süre:1m 15s