Soru

Zorluk: OrtaSocial Engineering Attacks and Vectors

A financial analyst receives an unexpected telephone call from an individual claiming to be a senior analyst from the corporate internal audit department. The caller states that an urgent financial discrepancy was flagged during an ongoing audit and directs the analyst to verbally confirm their network login credentials and multi-factor authentication code to verify their identity before the system is locked out. Which social engineering attack vector is demonstrated in this scenario?

  1. VishingCevap
  2. B
    Smishing
  3. C
    Watering hole attack
  4. D
    Whaling

Cevap

The correct attack vector is vishing.
The correct option is vishing because the social engineering attempt was carried out using a direct voice telephone call to manipulate the victim into revealing sensitive login credentials and multi-factor authentication tokens.

Adım Adım Çözüm

1
Analyze the communication medium described in the incident scenario.
The attack occurs via a direct telephone call (voice communication).
Identifying the transmission channel differentiates voice-based social engineering from email or text messaging.
2
Evaluate the attacker's tactic and objective.
The caller uses pretexting (impersonating an internal auditor) to create urgency and trick the victim into sharing sensitive authentication factors.
Social engineering attacks often leverage trust and urgency to bypass standard security procedures.
3
Map the medium and tactic to standard security taxonomy terminology.
Voice-based phishing conducted over the telephone is defined as vishing (voice phishing).
CompTIA Security+ distinguishes social engineering variants based on delivery mechanisms and target profiles.

Anahtar Kavram

Vishing (Voice Phishing)
Tahmini Süre:1m 0s
Bu soruyu puanla