Soru

Zorluk: OrtaSocial Engineering and Threat Types

A remote software engineer receives an unexpected phone call from an individual claiming to be a senior network administrator from the corporate IT helpdesk. The caller states that an urgent security patch requires immediate account validation and requests that the engineer approve a multifactor authentication (MFA) push notification sent to their mobile device. Which social engineering threat vector is primarily being conducted in this scenario?

  1. VishingCevap
  2. B
    Spear phishing
  3. C
    Whaling
  4. D
    Watering hole attack

Cevap

Vishing is the correct classification because the attack is conducted over a phone call (voice phishing) to manipulate the user into approving authentication access.
The attack uses telephone communication (voice phishing/vishing) to trick the user into granting access by approving an MFA push notification under the guise of an IT support request.

Adım Adım Çözüm

1
Analyze the communication channel used in the scenario stem.
The attack occurs via a live telephone phone call rather than email, web redirection, or SMS.
Social engineering threat types are largely categorized by their delivery medium and targeting scope.
2
Evaluate the attacker's tactic and objective.
The attacker impersonates IT support over the phone to convince the victim to approve an MFA push notification.
Voice-based social engineering aimed at tricking victims into revealing credentials or approving access requests is defined as vishing (voice phishing).

Anahtar Kavram

Social Engineering Delivery Vectors
Bu soruyu puanla