Soru

Zorluk: KolaySocial Engineering and Threat Types

A security technician is preparing training materials to help staff recognize different security risks. Match each threat type on the left with its correct description on the right.

  • Watering Hole AttackCompromising a specific website frequently visited by employees of a target organization to deliver malware.
  • WhalingA targeted phishing attack specifically directed at high-profile corporate executives or senior leaders.
  • Dumpster DivingPhysically searching through discarded trash or recycling bins to discover sensitive written information.
  • Logic BombMalicious code injected into a system that remains dormant until specified logical conditions or dates are met.

Cevap

Watering Hole Attack matches compromising a frequently visited website. Whaling matches targeted phishing against high-profile executives. Dumpster Diving matches physically searching trash bins for sensitive documents. Logic Bomb matches dormant malicious code triggered by specified logical conditions.
Watering Hole Attack pairs with compromising a trusted website used by a target group. Whaling pairs with phishing aimed directly at high-level executives. Dumpster Diving pairs with looking through paper trash for confidential data. Logic Bomb pairs with malicious code designed to execute when specific criteria are met.

Adım Adım Çözüm

1
Analyze the web-based attack targeting specific industry sites.
Watering Hole attack infects a third-party site frequented by employees of the target group.
Attackers exploit trust in a third-party site to compromise visitors automatically.
2
Identify the high-profile targeted social engineering email scam.
Whaling targets senior executives such as CEOs and CFOs.
Whaling is a specific category of spear phishing aimed exclusively at high-level leadership.
3
Identify the physical security threat vector.
Dumpster Diving involves looking through physical waste containers for sensitive documents.
Attackers search municipal trash for unredacted passwords, internal directories, or proprietary documents.
4
Identify the dormant condition-triggered malware.
Logic Bomb triggers malicious commands when specific events or dates occur.
Logic bombs lie dormant until predetermined parameters are met.

Anahtar Kavram

Social Engineering and Threat Vector Classification
Bu soruyu puanla