Soru

Zorluk: Çok zorSocial Engineering and Threat Types

A cybersecurity technician is reviewing recent security incident logs and physical security reports across an enterprise. Match each reported security incident scenario to its corresponding social engineering attack vector or threat classification.

  • A Chief Financial Officer receives an urgent email appearing to originate from the CEO, instructing them to execute an immediate wire transfer to a vendor for an undisclosed corporate acquisition.Whaling
  • An unauthorized individual holding a stack of large boxes closely follows an employee through a card-swipe secured entry door without presenting credentials.Tailgating
  • Employees seeking an internal benefits portal are redirected to a malicious web page after inadvertently entering 'corp-beneefits.com' into their browser navigation bar.Typosquatting
  • An attacker compromises a niche industry news site regularly visited by the company's defense research team in order to execute drive-by malware downloads on visitor systems.Watering Hole Attack

Cevap

The executive wire transfer request matches Whaling, unauthorized entry past electronic doors behind an employee matches Tailgating, redirection due to misspelled URLs matches Typosquatting, and compromising an industry news website frequented by targeted personnel matches a Watering Hole Attack.
Each attack vector corresponds directly to its standardized security classification: executive-targeted email coercion matches Whaling, unauthorized physical door following matches Tailgating, domain misdirection based on typing errors matches Typosquatting, and strategic compromise of a niche website frequented by specific targets matches a Watering Hole Attack.

Adım Adım Çözüm

1
Evaluate the incident involving targeted email fraud aimed at executive leadership for high-value financial theft.
Identify that spear phishing specifically directed at high-level executives is Whaling.
Whaling targets senior executives (such as CFOs or CEOs) to attempt high-profile financial fraud or data theft.
2
Evaluate the physical access security breach involving entry behind authorized personnel.
Identify that unauthenticated physical entry following an authorized person is Tailgating.
Tailgating relies on social courtesies or physical proximity to enter restricted areas without presenting credentials.
3
Evaluate the web redirection caused by user typographical errors in web addresses.
Identify that exploiting misspelled web domains to trick users is Typosquatting.
Typosquatting relies on user error when typing URLs into web browsers.
4
Evaluate the third-party website compromise strategy aimed at a specific employee demographic.
Identify that compromising a site frequently visited by the target audience is a Watering Hole Attack.
Watering hole attacks infect trusted third-party websites where intended targets naturally gather online.

Anahtar Kavram

Social Engineering Attack Vectors and Threat Classifications
Bu soruyu puanla