Soru

Zorluk: OrtaSocial Engineering Attacks and Vectors

An organization's security operations center (SOC) detects an incident where an employee received a text message on their mobile phone containing an urgent link to verify their corporate single sign-on (SSO) credentials on a fraudulent domain. Shortly after, an unknown attacker calls the IT helpdesk, posing as the employee and using previously gathered personal details to request an account recovery passcode. Which of the following social engineering vectors were directly utilized in this attack scenario? (Select TWO.)

  1. SmishingCevap
  2. VishingCevap
  3. C
    Watering hole attack
  4. D
    Dumpster diving

Cevap

The attack scenario directly utilized smishing and vishing.
Smishing and vishing are correct because the attacker used SMS text messages containing malicious links and telephone calls impersonating an employee to execute the credential harvesting and unauthorized access attempt.

Adım Adım Çözüm

1
Analyze the SMS message vector
Identified smishing due to fraudulent text messages sent to mobile devices.
Phishing delivered via short message service (SMS) is categorized specifically as smishing.
2
Analyze the phone call and impersonation vector
Identified vishing due to deceptive telephone interaction targeting the helpdesk.
Voice-based social engineering attempts conducted over the phone constitute vishing.

Anahtar Kavram

Social Engineering Attacks and Vectors
Bu soruyu puanla