Soru

Zorluk: ZorSocial Engineering and Threat Types

A field service technician receives an urgent SMS text message on their corporate-managed smartphone stating that their Mobile Device Management (MDM) profile has expired and network access will be terminated within one hour. The message directs the technician to tap a shortened URL to re-authenticate with their Active Directory domain credentials. Which of the following social engineering threat types is best illustrated by this attack vector?

  1. SmishingCevap
  2. B
    Vishing
  3. C
    Whaling
  4. D
    Typosquatting

Cevap

Smishing
Smishing (SMS Phishing) is a form of social engineering that uses SMS text messaging on mobile devices to trick victims into providing sensitive credentials or navigating to malicious websites. In this scenario, the attacker leveraged a fake MDM expiration notification sent via SMS to harvest Active Directory credentials.

Adım Adım Çözüm

1
Analyze the delivery channel described in the security incident
Identified the primary delivery vector as an urgent SMS text message sent to a corporate mobile device.
Social engineering attacks are primarily categorized by their initial delivery medium and target scope.
2
Evaluate the objective and deceptive tactics used in the payload
The message creates artificial urgency (1-hour expiration) and includes a shortened hyperlink designed to steal domain credentials.
Creating urgency and incorporating fraudulent login links are hallmark features of phishing attacks.
3
Map the SMS delivery medium to the standard CompTIA threat classification
Concluded that SMS-based phishing is formally categorized as Smishing (Short Message Service phishing).
Phishing over SMS is specifically designated as smishing, distinguishing it from email phishing or voice phishing.

Anahtar Kavram

Social Engineering Threat Types - Smishing
Bu soruyu puanla