Soru

Zorluk: KolaySocial Engineering and Threat Types

An executive assistant receives an urgent email appearing to come directly from the Chief Executive Officer (CEO) requesting an immediate transfer of funds to a new vendor. Simultaneously, a system administrator discovers that employee web traffic intended for the corporate banking portal is being secretly redirected to a fake login page through altered local host files. Which of the following threat types are demonstrated in this scenario? (Select TWO.)

  1. WhalingCevap
  2. PharmingCevap
  3. C
    Ransomware
  4. D
    Keylogger
  5. E
    Logic bomb

Cevap

Whaling and Pharming are the correct threat types.
Whaling accurately describes spoofing high-level executives to coerce employees into transferring funds. Pharming accurately describes corrupting host files or DNS settings to misdirect web traffic to spoofed websites.

Adım Adım Çözüm

1
Analyze the email attack vector targeting executive authorization.
Identify that impersonating executive leadership for fraudulent wire transfers is whaling.
Whaling targets or spoofs high-level executive positions to achieve high-impact malicious goals.
2
Analyze the network redirection method affecting web browsing.
Identify that modifying host files to secretly send users to a fraudulent banking site is pharming.
Pharming manipulates domain name resolution to hijack traffic without the user's explicit interaction with a malicious link.

Anahtar Kavram

Identifying executive-targeted phishing (whaling) and DNS/host-file web traffic misdirection (pharming).
Bu soruyu puanla