Soru

Zorluk: OrtaSocial Engineering Attacks and Vectors

Match each social engineering incident scenario on the left with the specific social engineering attack vector utilized on the right.

  • An attacker leaves malware-laden USB flash drives scattered around an enterprise facility parking lot, relying on curiosity to prompt employees to plug them into networked workstations.Baiting
  • An adversary compromises a legitimate third-party industry news portal frequently visited by an enterprise's defense research team to infect visiting users.Watering Hole Attack
  • An attacker contacts a system administrator while pretending to be an external compliance auditor and invents an urgent regulatory story to request privileged user access logs.Pretexting
  • An adversary intercepts a scheduled physical delivery of server hardware by convincing the logistics driver to deliver the shipment to a secondary unauthorized warehouse.Diversion Theft

Cevap

Baiting corresponds to leaving malware-laden drives in parking lots; Watering Hole Attack corresponds to compromising industry news sites visited by targets; Pretexting corresponds to inventing an auditor persona to obtain logs; Diversion Theft corresponds to re-routing physical shipments.
Each attack vector relies on distinct physical or psychological mechanisms: baiting uses physical curiosity lures; watering hole attacks exploit trust in common third-party websites; pretexting builds a false authoritative scenario to extract data; and diversion theft manipulates logistics to intercept physical equipment.

Adım Adım Çözüm

1
Analyze the first scenario involving physical media placed in parking lots to exploit victim curiosity.
Identify this as Baiting because it promises a lure (curiosity/free media) to deliver malicious payloads.
Baiting specifically leverages physical or digital enticement to convince victims to compromise security.
2
Analyze the second scenario involving a compromised third-party website regularly visited by target personnel.
Identify this as a Watering Hole Attack.
Watering hole attacks profile target web habits and infect a trusted watering hole site.
3
Analyze the third scenario where an attacker creates a false persona and fake urgency to extract information.
Identify this as Pretexting.
Pretexting requires constructing a believable role and scenario (the pretext) to trick a target into providing data or access.
4
Analyze the fourth scenario where physical shipments are rerouted during transit.
Identify this as Diversion Theft.
Diversion theft specifically targets transport, courier, or delivery supply chains to intercept physical assets.

Anahtar Kavram

Social Engineering Attack Vectors and Methods
Bu soruyu puanla