Soru

Zorluk: ZorSocial Engineering and Threat Types

Match each security threat or social engineering vector on the left with its corresponding attack scenario description on the right.

  • Spear PhishingA threat actor sends a carefully customized, fraudulent email specifically targeted to an organization's payroll manager requesting an immediate update to direct deposit records.
  • TailgatingAn unauthorized individual closely follows an employee carrying equipment through a badge-restricted door to gain entry without presenting valid credentials.
  • Watering Hole AttackA threat actor compromises a niche industry news site frequently visited by an organization's software developers to infect their workstations with drive-by malware.
  • Logic BombMalicious code planted within a critical server script remains dormant until a specific database condition or scheduled administrative event triggers its execution.

Cevap

Spear Phishing matches targeted communications aimed at specific job roles; Tailgating matches unauthorized physical entry following close behind an employee; Watering Hole Attack matches compromising trusted third-party websites visited by target users; Logic Bomb matches dormant malicious code triggered by defined system conditions.
Each attack vector correctly matches its operational description: Spear Phishing uses customized communications aimed at specific roles; Tailgating physically circumvents access control doors; Watering Hole Attack compromises external trusted websites to target specific groups; and a Logic Bomb relies on specific logical triggers to detonate dormant malicious code.

Adım Adım Çözüm

1
Identify the vector relying on customized digital communication targeting specific roles.
Spear Phishing corresponds to the tailored email targeting the payroll manager.
Spear phishing differs from general phishing because it is directed at a specific target individual or department with customized context.
2
Identify the physical security entry breach mechanism.
Tailgating corresponds to following an authorized employee into a secured building without badging in.
Tailgating exploits physical proximity and social courtesies to bypass physical access controls.
3
Identify the attack targeting trusted external websites.
Watering Hole Attack corresponds to infecting an industry news portal regularly visited by developers.
Watering hole attacks infect trusted third-party sites frequented by the target group to deliver malware.
4
Identify the software-based threat tied to specific conditional triggers.
Logic Bomb corresponds to dormant code executing upon a specific database condition or event.
Logic bombs remain inactive until predetermined logical criteria (such as dates, events, or missing file checks) occur.

Anahtar Kavram

Social Engineering Vectors and Malware Threat Classifications
Bu soruyu puanla