An organization's finance clerk receives an urgent email appearing to originate from the Chief Executive Officer, requesting an immediate wire transfer to close a confidential vendor contract. Shortly after receiving the email, the clerk receives a phone call from an individual claiming to be the CEO, urging them to bypass standard dual-authorization procedures due to extreme time constraints. Subsequent investigation reveals the attacker created a false narrative and spoofed the internal caller ID.
Which of the following social engineering attack vectors and techniques are directly demonstrated in this scenario? (Select TWO).
- Vishing, by using spoofed phone calls to verbally pressure the employee into bypassing controls.Cevap
- Pretexting, by constructing a fraudulent narrative of a time-sensitive vendor contract to justify ignoring standard procedures.Cevap
- CSmishing, by broadcasting malicious Short Message Service (SMS) text messages containing links to credential-harvesting portals.
- DWatering hole attack, by compromising a public website frequently visited by the organization's financial staff to deliver malware.
Cevap
The attack directly demonstrates vishing (using spoofed voice calls to pressure the employee) and pretexting (fabricating a time-sensitive contract scenario to bypass authorization protocols).
The scenario highlights two distinct social engineering techniques: vishing, which occurs when the attacker places a voice call pretending to be the CEO to pressure the staff member, and pretexting, which involves inventing a false scenario regarding an urgent vendor contract to persuade the staff member to bypass standard security verification.
Adım Adım Çözüm
Anahtar Kavram
Identifying Social Engineering Vectors and Techniques