Match each enterprise security incident scenario to the primary social engineering attack vector it exemplifies.
- An attacker compromises a legitimate, industry-specific news website frequently visited by target organization personnel to deliver drive-by exploit payloads.Watering Hole Attack
- An attacker sends highly tailored emails referencing internal project codes and executive names to trick specific financial staff into authorizing wire transfers.Spear Phishing
- An attacker carrying large packages closely follows an authorized employee through a card-restricted building entrance without presenting access credentials.Tailgating
- An attacker sends fraudulent SMS text messages impersonating corporate IT support to remote staff, directing them to a fake login portal to harvest credentials.Smishing
Cevap
The compromised industry news site matches Watering Hole Attack; the tailored executive emails match Spear Phishing; following an employee through a secure doorway matches Tailgating; and the fake IT support text messages match Smishing.
Each incident scenario aligns with a specific vector: Watering Hole attacks infect third-party websites commonly visited by target groups; Spear Phishing uses customized digital messages targeted at specific organizational roles; Tailgating exploits human politeness to breach physical entry points; and Smishing uses mobile SMS messaging to deceive targets.
Adım Adım Çözüm
Anahtar Kavram
Classification of Social Engineering Vectors and Tactical Indicators