An enterprise security operations center (SOC) detects an incident where remote executive assistants received customized SMS text messages appearing to originate from the corporate IT department. The messages contained links to a credential-harvesting landing page hosted on a typosquatted domain and warned that email access would be permanently suspended within two hours unless password re-verification was completed immediately. Which social engineering attack vector and primary principle of influence were executed in this scenario?
- Smishing leveraging the principle of urgencyCevap
- BVishing leveraging the principle of authority
- CSpear phishing leveraging the principle of consensus
- DWatering hole attack leveraging the principle of scarcity
Cevap
The attack vector is smishing, combined with the principle of urgency.
The correct response accurately identifies smishing as the attack vector because the communication took place over SMS text messages. It also correctly pairs this vector with the principle of urgency, as the attacker attempted to force quick compliance by establishing a two-hour deadline before access suspension.
Adım Adım Çözüm
Anahtar Kavram
Social Engineering Attacks and Vectors
Tahmini Süre:1m 30s