Soru

Zorluk: ZorSocial Engineering Attacks and Vectors

An organization's security operations center (SOC) detects an ongoing multi-vector attack targeting executive administrative assistants. The adversary uses spoofed Voice over IP (VoIP) calls to impersonate the Chief Financial Officer (CFO), claiming an urgent regulatory filing requires immediate authorization. Simultaneously, target personnel receive SMS messages containing links to a look-alike domain designed to clone the organization's single sign-on (SSO) authentication portal. Which of the following social engineering attack vectors and associated principles of influence are demonstrated in this campaign? (Select TWO).

  1. Vishing combined with the psychological principles of authority and urgencyCevap
  2. Smishing paired with domain typosquatting to facilitate credential harvestingCevap
  3. C
    Watering hole attack paired with drive-by download exploits
  4. D
    Shoulder surfing combined with physical tailgating to bypass multi-factor authentication

Cevap

The correct selections describe vishing utilizing authority and urgency, and smishing paired with domain typosquatting.
The campaign uses two direct communication channels: voice calls impersonating C-suite leadership to establish authority and impose time pressure (vishing using authority/urgency), and text messages directing targets to a visually fraudulent portal domain (smishing using typosquatting).

Adım Adım Çözüm

1
Analyze the voice communication channel described in the scenario.
The attacker used spoofed VoIP phone calls to impersonate executive leadership (CFO) and demand immediate action, which constitutes voice phishing (vishing) exploiting authority and urgency.
Vishing relies on telephony media combined with high-pressure social engineering tactics to manipulate targets.
2
Analyze the text messaging and web domain component of the scenario.
The attacker dispatched SMS text messages directing users to a look-alike authentication URL, representing SMS phishing (smishing) leveraging domain typosquatting.
Smishing utilizes text messaging to deliver malicious links, while typosquatting exploits minor URL differences to deceive users during credential harvesting.
3
Evaluate and eliminate incorrect social engineering definitions.
Watering hole attacks infect strategic web locations, while shoulder surfing requires direct physical observation of a user's screen or keyboard; neither corresponds to remote telephone or text campaigns.
Distinguishing between communication delivery mechanisms and physical/passive vectors is required to identify social engineering threats accurately.

Anahtar Kavram

Identification of Social Engineering Attack Vectors and Principles of Influence
Bu soruyu puanla