Match each social engineering attack vector or technique on the left with the enterprise incident scenario on the right that best demonstrates its execution.
- PharmingAn attacker alters host resolution settings on a local server to corrupt DNS traffic, silently redirecting users to an illegitimate site despite typing the correct URL.
- Quid Pro QuoAn adversary contacts end users claiming to be IT support offering an expedited system speed upgrade if the user shares their account password.
- HoaxA widespread email alerts staff to an alleged critical zero-day virus and urges users to delete essential system files to stop the threat.
- Dumpster DivingAn unauthorized individual sifts through external waste receptacles to recover printed internal phone rosters and unredacted organizational charts.
Cevap
Pharming matches the DNS/host file redirection scenario; Quid Pro Quo matches offering an IT upgrade service in exchange for credentials; Hoax matches the false virus alert instructing file deletion; Dumpster Diving matches searching physical waste bins for discarded documents.
Each attack vector is paired correctly according to its characteristic method: Pharming alters name resolution to redirect traffic, Quid Pro Quo exchanges a service for credentials, Hoax disseminates false alarms to provoke self-harming behavior, and Dumpster Diving physically recovers sensitive discarded items from trash bins.
Adım Adım Çözüm
Anahtar Kavram
Social engineering attack vectors and operational techniques
Tahmini Süre:1m 30s