Soru

Zorluk: KolaySocial Engineering Attacks and Vectors

An enterprise security analyst investigates an incident where several corporate accounts were compromised. The investigation reveals that employees received text messages on their mobile devices directing them to a fake login site to verify credentials. Additionally, the attacker placed phone calls to affected staff while pretending to be internal IT personnel to convince them to approve multi-factor authentication (MFA) push notifications. Which of the following social engineering attack vectors were directly executed in this campaign? (Select TWO.)

  1. SmishingCevap
  2. VishingCevap
  3. C
    Watering hole attack
  4. D
    Typosquatting

Cevap

The threat actor utilized smishing (SMS-based phishing) and vishing (voice-based phishing) during the attack.
The scenario describes two specific delivery mediums: text messages (SMS) used to send malicious links, which defines smishing; and voice phone calls used to manipulate employees into approving MFA push notifications, which defines vishing.

Adım Adım Çözüm

1
Analyze the text message delivery mechanism described in the scenario.
Identify that text messages sent to mobile devices directing users to a fake site constitute smishing.
Smishing is social engineering performed specifically over SMS communications.
2
Analyze the voice call delivery mechanism described in the scenario.
Identify that phone calls from an attacker posing as IT personnel constitute vishing.
Vishing involves voice calls (telephone/VoIP) to impersonate trusted entities and deceive victims.

Anahtar Kavram

Social Engineering Attack Vectors (Smishing vs. Vishing)
Bu soruyu puanla