Soru

Zorluk: OrtaSocial Engineering and Threat Types

An enterprise employee contacts the helpdesk after a pop-up window appears on their web browser claiming their computer is severely infected with malware. The pop-up instructs the user to call an unverified toll-free technical support number immediately to purchase remediation software. The company's installed security software indicates the operating system is clean. Which of the following social engineering threat types is being attempted?

  1. ScarewareCevap
  2. B
    Spear phishing
  3. C
    Pretexting
  4. D
    Watering hole attack

Cevap

The threat described is scareware, which uses false security warnings and fear tactics to manipulate users into taking harmful financial or operational actions.
Scareware leverages psychological pressure and fake system alerts to convince victims that their device is compromised, prompting them to pay for fake software or call rogue support numbers.

Adım Adım Çözüm

1
Analyze the indicators provided in the scenario.
The user received an unexpected pop-up claiming malware infection and demanding immediate phone contact/payment, while installed antivirus tools report clean status.
Identifying tactics such as coercive urgency, false infection messages, and solicitation of payment helps isolate the attack method.
2
Differentiate between threat classifications.
The scenario highlights anxiety-driven intimidation via fake warnings rather than targeted email messaging (spear phishing), persona fabrication (pretexting), or site compromises (watering hole).
Scareware specifically utilizes fake security notifications to trick users into installing rogue software or making payments.

Anahtar Kavram

Scareware and Social Engineering Threat Classification
Tahmini Süre:1m 0s
Bu soruyu puanla