Soru

Zorluk: OrtaSocial Engineering Attacks and Vectors

During a malware investigation, an incident responder discovers that several engineers in an organization had their workstations infected after visiting an authentic, third-party software development forum that they frequently use for work. The attacker had previously breached the forum and injected a malicious drive-by download script targeting visitors originating from the organization's corporate IP range. Which of the following social engineering attack vectors was executed by the threat actor?

  1. Watering hole attackCevap
  2. B
    Spear phishing
  3. C
    Typosquatting
  4. D
    Pretexting

Cevap

Watering hole attack
The correct answer is watering hole attack. In a watering hole attack, threat actors observe or predict which authentic websites a target group frequently visits, breach one of those sites, and plant malicious code to infect visitors from the target organization.

Adım Adım Çözüm

1
Analyze the attack mechanism described in the scenario
The adversary compromised an authentic, trusted third-party website commonly frequented by the target group to deliver malware.
Identifying the delivery channel distinguishes site-based passive exploitation from direct communication attacks.
2
Compare the attack characteristics against social engineering vector definitions
Planting malware on a site known to be visited by specific victims matches the definition of a watering hole attack.
Watering hole tactics specifically target sites trusted by a specific organization or demographic.

Anahtar Kavram

Watering Hole Attack Vector Identification
Tahmini Süre:1m 0s
Bu soruyu puanla