Soru

Zorluk: ZorSocial Engineering Attacks and Vectors

An organization's security team identifies that several software developers received personalized email messages appearing to originate from their version control platform administrator. The messages claimed that due to a critical security compliance violation, their repository access would be suspended within 90 minutes unless they logged into a specified web portal to verify their identity. The link provided led to a counterfeit authentication portal hosted on a visually similar, typo-registered domain designed to harvest credentials. Which of the following social engineering attack vectors and influence principles were directly employed in this campaign? (Select TWO).

  1. Spear phishing aimed at specific corporate rolesCevap
  2. B
    Watering hole tactics compromising a shared developer site
  3. Urgency leveraged to bypass critical reasoningCevap
  4. D
    Smishing delivered over cellular SMS channels

Cevap

The attack utilized spear phishing targeted at software developers and leveraged the psychological principle of urgency by threatening imminent account suspension.
The scenario describes spear phishing because the attackers created customized, role-specific email lures targeting software developers. Additionally, the attackers leveraged urgency by establishing an immediate 90-minute deadline with severe consequences (loss of repository access) to prevent victims from stopping to verify the request.

Adım Adım Çözüm

1
Analyze the communication channel and target specificity
The messages were emails tailored to software developers pretending to originate from their internal platform administrator, characteristic of spear phishing.
Spear phishing targets specific roles or individuals using customized lures rather than broad, generic phishing campaigns.
2
Identify the psychological driver used in the lure
The message forced compliance by establishing a 90-minute deadline before account deactivation.
Creating a time-sensitive crisis exploits urgency to prompt immediate compliance before verification can occur.
3
Evaluate and rule out incorrect vector classifications
Watering hole tactics and smishing do not match the direct email delivery mechanism and malicious portal vector described.
Watering hole attacks infect trusted third-party websites, and smishing uses mobile text messaging.

Anahtar Kavram

Spear Phishing and Principles of Influence (Urgency)
Bu soruyu puanla