During a security incident investigation, an IT support technician discovers that several employees in the finance department had their credentials compromised. Log analysis reveals that none of the affected employees received fraudulent emails or suspicious direct phone calls. Instead, all compromised users had routinely visited a highly specialized, trusted third-party regulatory news website that attackers secretly compromised to inject malicious credential-harvesting code. Which of the following threat types BEST describes this attack?
- Watering hole attackCevap
- BSpear phishing
- CPretexting
- DTyposquatting
Cevap
Watering hole attack
The correct answer identifies a watering hole attack. In a watering hole attack, an attacker identifies and compromises a specific, trusted website frequented by employees of a targeted organization or group. When the targets visit the legitimate site, malicious scripts capture credentials or infect their systems.
Adım Adım Çözüm
Anahtar Kavram
Watering Hole Attack Identification
Tahmini Süre:1m 0s