Soru

Zorluk: OrtaSocial Engineering and Threat Types

An IT support technician receives multiple tickets from accounting department staff members who report being directed to a suspicious web page when attempting to access the official corporate portal at `https://ledger.company.com`. The technician verifies that users entered the exact, correct web address into their browser address bars. Further investigation reveals that local hosts files are intact, but an attacker successfully compromised local DNS server records to point the corporate portal domain name to an external malicious server. Which of the following threat types best describes this attack?

  1. PharmingCevap
  2. B
    Typosquatting
  3. C
    Spear phishing
  4. D
    Watering hole attack

Cevap

Pharming is the correct answer because it involves manipulating DNS records or system host files to silently redirect requests for legitimate web addresses to malicious destinations.
The correct option is pharming because it specifically describes an attack method that alters DNS server records or host configuration files to automatically redirect legitimate web traffic to a rogue site.

Adım Adım Çözüm

1
Analyze the delivery mechanism of the security incident.
Users typed the correct corporate domain URL, but domain resolution directed traffic to an external malicious IP address due to DNS server record manipulation.
Identifying whether the issue stems from user typographical errors, phishing messages, or DNS infrastructure tampering clarifies the exact threat vector.
2
Classify the threat based on CompTIA security definitions.
Traffic redirection achieved via host file alteration or DNS server cache poisoning is classified specifically as pharming.
Pharming attacks exploit network name resolution infrastructure rather than relying on social engineering email links or user typing mistakes.

Anahtar Kavram

Pharming and Infrastructure Manipulation
Bu soruyu puanla