Match each security incident description on the left with the corresponding social engineering or threat type on the right.
- An unauthorized individual carrying heavy equipment boxes asks an authorized employee to hold open a secure badge-access entrance.Piggybacking
- A technician receives an email directing them to a malicious administrative portal featuring a domain name with a transposed character.Typosquatting
- A remote worker receives a phone call from an attacker impersonating internal IT helpdesk staff requesting credential verification to resolve a pending ticket.Pretexting
- A malicious script installed on a database server is configured to execute and wipe records if a specific employee user account remains inactive for 30 days.Logic bomb
Cevap
Holding a door open with permission describes Piggybacking. A spoofed URL with a transposed character describes Typosquatting. Impersonating IT personnel over the phone describes Pretexting. Code triggered by account inactivity describes a Logic bomb.
Each attack scenario matches its specific threat classification based on method and vector: Piggybacking relies on social courtesy for physical access, Typosquatting exploits web address spelling mistakes, Pretexting creates a fake persona/scenario to manipulate targets, and a Logic bomb executes malicious payloads when specific logical conditions occur.
Adım Adım Çözüm
Anahtar Kavram
Social Engineering Tactics and Threat Vectors