An organization's security operations center (SOC) detects an incident where an employee received a text message on their mobile phone containing an urgent link to verify their corporate single sign-on (SSO) credentials on a fraudulent domain. Shortly after, an unknown attacker calls the IT helpdesk, posing as the employee and using previously gathered personal details to request an account recovery passcode. Which of the following social engineering vectors were directly utilized in this attack scenario? (Select TWO.)
- SmishingCevap
- VishingCevap
- CWatering hole attack
- DDumpster diving
Cevap
The attack scenario directly utilized smishing and vishing.
Smishing and vishing are correct because the attacker used SMS text messages containing malicious links and telephone calls impersonating an employee to execute the credential harvesting and unauthorized access attempt.
Adım Adım Çözüm
Anahtar Kavram
Social Engineering Attacks and Vectors