Threats, Vulnerabilities, and Mitigations

490 soru

Soru 441Soru

Match each social engineering attack vector on the left with its corresponding operational incident scenario description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Tailgating
Watering Hole Attack
Smishing
Shoulder Surfing

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Tailgating matches unbadged physical entry by following authorized personnel; Watering Hole Attack matches compromising a trusted, frequently visited website; Smishing matches deceptive SMS text messages containing malicious links; Shoulder Surfing matches direct visual observation of screens or keyboard inputs.
Each attack vector correctly maps to its distinct channel and method of execution: tailgating exploits physical access doors, watering hole attacks compromise frequented web destinations, smishing relies on mobile SMS delivery, and shoulder surfing uses line-of-sight observation.

Adım Adım Çözüm

1
Analyze the physical access vector
Identify that gaining entry behind an authorized person without badge authorization defines Tailgating.
Tailgating relies on physical proximity and courtesy or distraction at access control points.
2
Analyze the web-based targeted vector
Identify that infecting a specific third-party portal routinely visited by personnel defines a Watering Hole Attack.
Watering hole attacks leverage the implicit trust users place in industry-specific sites.
3
Analyze the mobile cellular and visual observation vectors
Identify cellular text message phishing as Smishing, and covert visual monitoring of user screens as Shoulder Surfing.
Smishing is specific to SMS communication protocols, while shoulder surfing leverages direct line of sight in physical spaces.

Anahtar Kavram

Social Engineering Attack Vectors and Methods
Soru 442Soru

During a physical security assessment, security auditors observe an unauthorized individual entering a secured facility by following closely behind a credentialed staff member through a badge-access door. Once inside the facility, the individual secretly records an administrator entering sensitive credentials onto a workstation keyboard from a nearby seating area. Which of the following social engineering vectors were executed during this physical security breach? (Select TWO)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Tailgating; Shoulder surfing

Cevap

The correct social engineering attack vectors are tailgating and shoulder surfing.
Tailgating is correctly identified because the intruder physically followed a credentialed user through an access point without authenticating. Shoulder surfing is correctly identified because the intruder observed the physical entry of confidential credentials onto a workstation keyboard.

Adım Adım Çözüm

1
Analyze the physical access mechanism described in the scenario.
The unauthorized individual entered the secure facility by following an authorized employee through a badge-access door without credential verification, defining tailgating.
Tailgating relies on physical proximity to bypass electronic entry controls.
2
Analyze the information-gathering method described in the scenario.
The intruder visually observed and recorded an administrator entering sensitive credentials onto a keyboard from a nearby location, defining shoulder surfing.
Shoulder surfing relies on direct observation of user inputs or displays without verbal interaction.

Anahtar Kavram

Physical Social Engineering Vectors (Tailgating and Shoulder Surfing)
Soru 443Soru

An organization's finance clerk receives an urgent email appearing to originate from the Chief Executive Officer, requesting an immediate wire transfer to close a confidential vendor contract. Shortly after receiving the email, the clerk receives a phone call from an individual claiming to be the CEO, urging them to bypass standard dual-authorization procedures due to extreme time constraints. Subsequent investigation reveals the attacker created a false narrative and spoofed the internal caller ID.

Which of the following social engineering attack vectors and techniques are directly demonstrated in this scenario? (Select TWO).

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Vishing, by using spoofed phone calls to verbally pressure the employee into bypassing controls.; Pretexting, by constructing a fraudulent narrative of a time-sensitive vendor contract to justify ignoring standard procedures.

Cevap

The attack directly demonstrates vishing (using spoofed voice calls to pressure the employee) and pretexting (fabricating a time-sensitive contract scenario to bypass authorization protocols).
The scenario highlights two distinct social engineering techniques: vishing, which occurs when the attacker places a voice call pretending to be the CEO to pressure the staff member, and pretexting, which involves inventing a false scenario regarding an urgent vendor contract to persuade the staff member to bypass standard security verification.

Adım Adım Çözüm

1
Analyze the communication channels used in the scenario.
Identified direct email impersonation accompanied by a phone call targeting the employee.
Social engineering attack classification depends heavily on the medium and delivery vector utilized by the threat actor.
2
Evaluate the verbal phone call component.
The phone call represents vishing (voice phishing).
Vishing specifically refers to social engineering conducted via voice telephone systems.
3
Evaluate the false narrative and justification used to bypass security controls.
The fabricated time-sensitive vendor contract represents pretexting.
Pretexting involves establishing an invented situation or identity to manipulate the target into compliance.

Anahtar Kavram

Identifying Social Engineering Vectors and Techniques
Soru 444Soru

Match each social engineering incident scenario on the left with the specific social engineering attack vector utilized on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

An attacker leaves malware-laden USB flash drives scattered around an enterprise facility parking lot, relying on curiosity to prompt employees to plug them into networked workstations.
An adversary compromises a legitimate third-party industry news portal frequently visited by an enterprise's defense research team to infect visiting users.
An attacker contacts a system administrator while pretending to be an external compliance auditor and invents an urgent regulatory story to request privileged user access logs.
An adversary intercepts a scheduled physical delivery of server hardware by convincing the logistics driver to deliver the shipment to a secondary unauthorized warehouse.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Baiting corresponds to leaving malware-laden drives in parking lots; Watering Hole Attack corresponds to compromising industry news sites visited by targets; Pretexting corresponds to inventing an auditor persona to obtain logs; Diversion Theft corresponds to re-routing physical shipments.
Each attack vector relies on distinct physical or psychological mechanisms: baiting uses physical curiosity lures; watering hole attacks exploit trust in common third-party websites; pretexting builds a false authoritative scenario to extract data; and diversion theft manipulates logistics to intercept physical equipment.

Adım Adım Çözüm

1
Analyze the first scenario involving physical media placed in parking lots to exploit victim curiosity.
Identify this as Baiting because it promises a lure (curiosity/free media) to deliver malicious payloads.
Baiting specifically leverages physical or digital enticement to convince victims to compromise security.
2
Analyze the second scenario involving a compromised third-party website regularly visited by target personnel.
Identify this as a Watering Hole Attack.
Watering hole attacks profile target web habits and infect a trusted watering hole site.
3
Analyze the third scenario where an attacker creates a false persona and fake urgency to extract information.
Identify this as Pretexting.
Pretexting requires constructing a believable role and scenario (the pretext) to trick a target into providing data or access.
4
Analyze the fourth scenario where physical shipments are rerouted during transit.
Identify this as Diversion Theft.
Diversion theft specifically targets transport, courier, or delivery supply chains to intercept physical assets.

Anahtar Kavram

Social Engineering Attack Vectors and Methods
Soru 445Soru

During a malware investigation, an incident responder discovers that several engineers in an organization had their workstations infected after visiting an authentic, third-party software development forum that they frequently use for work. The attacker had previously breached the forum and injected a malicious drive-by download script targeting visitors originating from the organization's corporate IP range. Which of the following social engineering attack vectors was executed by the threat actor?

Cevabı ve açıklamayı göster

Cevap: Watering hole attack

Cevap

Watering hole attack
The correct answer is watering hole attack. In a watering hole attack, threat actors observe or predict which authentic websites a target group frequently visits, breach one of those sites, and plant malicious code to infect visitors from the target organization.

Adım Adım Çözüm

1
Analyze the attack mechanism described in the scenario
The adversary compromised an authentic, trusted third-party website commonly frequented by the target group to deliver malware.
Identifying the delivery channel distinguishes site-based passive exploitation from direct communication attacks.
2
Compare the attack characteristics against social engineering vector definitions
Planting malware on a site known to be visited by specific victims matches the definition of a watering hole attack.
Watering hole tactics specifically target sites trusted by a specific organization or demographic.

Anahtar Kavram

Watering Hole Attack Vector Identification
Tahmini Süre:1m 0s
Soru 446Soru

A financial analyst receives an unexpected telephone call from an individual claiming to be a senior analyst from the corporate internal audit department. The caller states that an urgent financial discrepancy was flagged during an ongoing audit and directs the analyst to verbally confirm their network login credentials and multi-factor authentication code to verify their identity before the system is locked out. Which social engineering attack vector is demonstrated in this scenario?

Cevabı ve açıklamayı göster

Cevap: Vishing

Cevap

The correct attack vector is vishing.
The correct option is vishing because the social engineering attempt was carried out using a direct voice telephone call to manipulate the victim into revealing sensitive login credentials and multi-factor authentication tokens.

Adım Adım Çözüm

1
Analyze the communication medium described in the incident scenario.
The attack occurs via a direct telephone call (voice communication).
Identifying the transmission channel differentiates voice-based social engineering from email or text messaging.
2
Evaluate the attacker's tactic and objective.
The caller uses pretexting (impersonating an internal auditor) to create urgency and trick the victim into sharing sensitive authentication factors.
Social engineering attacks often leverage trust and urgency to bypass standard security procedures.
3
Map the medium and tactic to standard security taxonomy terminology.
Voice-based phishing conducted over the telephone is defined as vishing (voice phishing).
CompTIA Security+ distinguishes social engineering variants based on delivery mechanisms and target profiles.

Anahtar Kavram

Vishing (Voice Phishing)
Tahmini Süre:1m 0s
Soru 447Soru

Match each enterprise security incident scenario on the left with the specific social engineering attack vector utilized on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

An attacker registers a domain name containing a common misspelling of a corporate web portal to harvest employee authentication credentials.
An attacker leaves malware-infected USB flash drives scattered in the employee parking lot hoping someone inserts one into a company workstation.
An attacker contacts a shipping department while impersonating a logistics dispatcher to trick staff into redirecting a valuable shipment to an offsite address.
An attacker submits a fraudulent payment request to the accounts payable department designed to mimic a routine bill from an established third-party vendor.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The credential harvesting site using a misspelled domain matches Typosquatting; the malware-laden flash drives left in the parking lot match Baiting; the fraudulent redirection of a shipment matches Diversion theft; and the fake vendor payment request matches Invoice fraud.
Each attack vector is correctly paired based on its primary delivery mechanism: Typosquatting uses deceptive URLs based on spelling errors; Baiting relies on physical media traps; Diversion theft manipulates physical delivery routes; and Invoice fraud uses deceptive billing requests to siphon corporate funds.

Adım Adım Çözüm

1
Analyze the web portal scenario involving misspelled domain registration.
Identify that exploiting typos in URLs to host spoofed credential-harvesting sites is typosquatting.
Typosquatting relies on user typographical mistakes when typing web addresses.
2
Analyze the physical media scenario involving unattended USB drives.
Identify that leaving physical media to entice curiosity is baiting.
Baiting relies on offering a physical item or incentive that promises a reward or satisfies curiosity.
3
Analyze the logistics scenario involving redirected shipments.
Identify that intercepting or altering courier deliveries is diversion theft.
Diversion theft specifically targets the supply chain or delivery process to steal physical goods.
4
Analyze the financial payment request scenario.
Identify that spoofing vendor billing documents to manipulate accounts payable is invoice fraud.
Invoice fraud uses pretexting and spoofed documentation to trick accounting into unauthorized disbursements.

Anahtar Kavram

Social Engineering Attack Vectors
Soru 448Soru

An enterprise security operations center (SOC) discovers that several employees mistakenly submitted their corporate domain credentials to an external login portal. The malicious portal was hosted on `login.acme-corp.net`, whereas the legitimate enterprise single sign-on (SSO) portal is `login.acme-corp.com`. The attacker registered the alternate top-level domain to impersonate the enterprise authentication interface. Which of the following social engineering attack vectors was primarily executed by the attacker?

Cevabı ve açıklamayı göster

Cevap: Typosquatting

Cevap

Typosquatting
Typosquatting (also known as URL hijacking) relies on registering domain names that closely resemble legitimate enterprise domain names—such as changing the top-level domain extension from `.com` to `.net` or inserting common misspellings—to trick users into delivering credentials to an attacker-controlled infrastructure.

Adım Adım Çözüm

1
Analyze the incident indicator
Identified that the attacker registered `login.acme-corp.net` to imitate the legitimate domain `login.acme-corp.com`.
Determining how the malicious destination was constructed reveals the specific vector utilized.
2
Map the technique to social engineering categories
Registering slightly modified or alternate top-level domain names to trick users into believing a fake site is authentic defines URL hijacking/typosquatting.
Typosquatting relies on user misdirection through minor textual variations or domain extension swaps.

Anahtar Kavram

Typosquatting and Domain Impersonation
Soru 449Soru

A security analyst is reviewing incident reports from remote staff who experienced a coordinated social engineering campaign. Several employees received text messages on their corporate mobile devices containing links to a counterfeit login portal, while other employees received phone calls from an attacker posing as IT support attempting to obtain credential resets. Which of the following social engineering attack vectors were executed during this incident? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Smishing; Vishing

Cevap

Smishing and Vishing
Smishing describes social engineering attacks delivered via SMS text messages, matching the text messages sent to corporate mobile devices. Vishing describes voice-based phishing over telephone calls, matching the attacker calling employees while impersonating IT support staff. Both options accurately reflect the attack vectors described in the scenario.

Adım Adım Çözüm

1
Identify the vector used in the text message delivery channel.
SMS text messages sent to mobile devices with malicious links constitute smishing.
Phishing attempts conducted via Short Message Service (SMS) are defined as smishing.
2
Identify the vector used in the telephone delivery channel.
Telephone calls where an attacker impersonates IT support personnel constitute vishing.
Voice-based telephone social engineering is defined as vishing.
3
Distinguish correct communication channels from web-based or domain-based attack techniques.
Watering hole attacks and typosquatting do not involve direct text message or voice communication channels.
Watering hole attacks compromise specific websites, while typosquatting targets URL misspellings.

Anahtar Kavram

Identification of social engineering attack vectors based on communication medium
Soru 450Soru

An administrative assistant at a logistics firm receives an urgent text message on their corporate mobile phone from an unverified short code claiming to be the company's Vice President of Operations. The message asserts that a supplier invoice must be authorized immediately via a provided short link to prevent supply chain disruption, warning that delay will result in severe administrative penalty. Which social engineering attack vector and primary influence principle are demonstrated in this scenario?

Cevabı ve açıklamayı göster

Cevap: Smishing utilizing authority and urgency

Cevap

Smishing utilizing authority and urgency
The attack uses SMS text messaging as its transport mechanism, which defines smishing. The attacker leverages the victim's obedience to corporate hierarchy (authority) and creates artificial time pressure backed by threats of punishment (urgency) to force compliance without verification.

Adım Adım Çözüm

1
Identify the communication medium used in the attack scenario.
The message was received via mobile text messaging (SMS), which defines the attack vector as smishing.
Phishing variants are distinguished primarily by medium: email (phishing/spear phishing), voice call (vishing), or SMS (smishing).
2
Analyze the target of the attack versus the identity assumed by the threat actor.
The target is an administrative assistant, while the attacker claims to be a Vice President.
This shows an executive impersonation attack aimed at a staff member, excluding whaling (which targets executives).
3
Determine the psychological influence principles employed by the attacker.
The attacker invokes the rank of Vice President (authority) and demands immediate action under threat of penalty (urgency).
Social engineering tactics manipulate human behavioral triggers to bypass formal operational controls.

Anahtar Kavram

Social Engineering Attack Vectors and Principles of Influence
Soru 451Soru

Match each enterprise security incident scenario on the left with the corresponding social engineering attack vector or technique on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

An attacker leaves custom USB drives labeled 'Q3 Executive Salary Review' on tables in the corporate cafeteria to trick curious employees into plugging them into company workstations.
An attacker fabricates a detailed persona as an external compliance auditor and calls human resources to request temporary administrative access credentials under the guise of an unannounced regulatory review.
An attacker intercepts communication between a firm and its regular supplier, replacing the supplier's legitimate wire transfer payment instructions with attacker-controlled bank details.
An attacker sends a highly targeted email directly to the Chief Executive Officer, referencing private board meeting topics to urgently demand a transfer of funds to avoid a fictitious regulatory fine.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The correct pairings match: (1) USB drives left in the cafeteria to Baiting; (2) Fictional compliance auditor identity requesting access to Pretexting; (3) Intercepting supplier wire payment details to Invoice Switching; and (4) Highly targeted email aimed at the CEO to Whaling.
Each attack vector is correctly identified by evaluating its delivery channel, target profile, and deception technique: Baiting uses physical curiosity triggers; Pretexting uses a crafted false persona; Invoice Switching alters legitimate transaction details; and Whaling specifically targets high-ranking executives.

Adım Adım Çözüm

1
Analyze the physical media scenario (cafeteria USB drives)
Identified as Baiting, which relies on offering an appealing item (curiosity hook) to entice a victim into executing malware.
Baiting relies on physical or digital promises that exploit curiosity or greed.
2
Analyze the identity fraud scenario (fake auditor calling HR)
Identified as Pretexting, which involves inventing a believable context or role to manipulation individuals into surrendering information.
Pretexting requires establishing a fictional background story and role prior to requesting sensitive access.
3
Analyze the payment detail tampering scenario (modifying vendor bank info)
Identified as Invoice Switching, where legitimate transactional data is modified to divert money.
Invoice switching explicitly targets financial workflows by modifying beneficiary banking details.
4
Analyze the high-level executive targeting scenario (email to CEO)
Identified as Whaling, a specialized subcategory of spear phishing directed specifically at C-suite personnel.
Phishing attempts specifically aimed at senior leadership or high-value targets are categorized as whaling.

Anahtar Kavram

Social Engineering Attack Classification
Soru 452Soru

A security analyst is investigating a multi-vector social engineering campaign targeting an organization's accounting department. The incident report highlights two distinct activities: first, an attacker placed a direct phone call to a payroll clerk, posing as an executive and demanding an immediate wire transfer; second, several accountants received SMS text messages on their corporate mobile devices containing links to a fraudulent login page designed to harvest credentials. Which of the following social engineering attack vectors were executed during this campaign? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Vishing (voice phishing) targeting the payroll clerk via direct telephone communications.; Smishing (SMS phishing) targeting accounting staff through text messages.

Cevap

Vishing (voice phishing) targeting the payroll clerk via direct telephone communications, and Smishing (SMS phishing) targeting accounting staff through text messages.
The campaign incorporated vishing because the attacker initiated telephone calls to impersonate an executive, leveraging voice communication. Additionally, smishing was executed through SMS text messages delivered to employee mobile devices containing malicious credential harvesting links.

Adım Adım Çözüm

1
Analyze the first incident activity involving telephone communications.
The attacker used direct voice calls to impersonate an executive, which corresponds directly to vishing (voice phishing).
Vishing specifies telephone or voice-based social engineering.
2
Analyze the second incident activity involving text messages sent to mobile phones.
The attacker sent SMS messages with credential-harvesting links, which corresponds directly to smishing (SMS phishing).
Smishing is defined by using SMS messages as the primary delivery vector.

Anahtar Kavram

Distinguishing social engineering vectors based on communication medium (voice vs. SMS text message)
Tahmini Süre:1m 30s
Soru 453Soru

An enterprise system administrator receives an unsolicited telephone call from an individual claiming to represent the organization's central data center team. The caller states that an emergency database synchronization failure is occurring and demands that the administrator immediately provide their two-factor authentication bypass code to prevent widespread data loss. Which social engineering attack vector is the caller primarily utilizing?

Cevabı ve açıklamayı göster

Cevap: Vishing

Cevap

The correct answer is vishing, as the attack relies on voice communication over the telephone combined with an urgent pretext.
The attack relies on an interactive voice phone call to manipulate the victim into exposing sensitive multi-factor authentication credentials under the guise of an urgent technical issue. This directly defines vishing (voice phishing).

Adım Adım Çözüm

1
Identify the communication medium used by the attacker in the scenario.
The attack occurs via an unsolicited telephone call.
The medium (voice call vs SMS vs email vs web) distinguishes primary social engineering attack vector categories.
2
Analyze the adversary's tactic and psychological trigger.
The attacker creates a fake technical emergency (pretexting) to create urgency over a phone call.
Voice-based social engineering combined with scenario-based pretexting defines voice phishing (vishing).
3
Select the social engineering term matching voice-based communication.
Vishing is the correct classification.
Vishing specifically denotes phishing attacks conducted over voice telephone systems.

Anahtar Kavram

Vishing and Voice-Based Pretexting Attacks
Soru 454Soru

During a routine security audit, an incident handler observes that several software developers in a research division were redirected to a compromised third-party technical discussion forum they frequently visit. The compromised forum silently downloaded a malicious browser extension to harvest API tokens used in the company's continuous integration pipeline. Which of the following social engineering techniques best describes this initial access vector?

Cevabı ve açıklamayı göster

Cevap: Watering hole attack

Cevap

Watering hole attack
A watering hole attack occurs when an adversary anticipates the web resources a specific target group frequents, compromises one or more of those websites, and uses them to infect visitors from the target organization.

Adım Adım Çözüm

1
Analyze the attack delivery medium described in the scenario.
The attack compromised a legitimate third-party website (a technical discussion forum) that a targeted group (research division developers) routinely visits.
Identifying whether the attack used direct communication, physical devices, or a shared compromised web resource determines the specific attack vector.
2
Compare the scenario details against social engineering attack definitions.
Compromising a specific site frequented by targets to deliver malware without direct message interaction defines a watering hole attack.
Watering hole attacks leverage implicit trust in established community resources rather than direct email or telephone solicitation.

Anahtar Kavram

Watering Hole Attack Identification
Tahmini Süre:1m 15s
Soru 455Soru

Match each social engineering attack vector to its corresponding real-world enterprise incident scenario.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Whaling
Pretexting
Shoulder surfing
Diversion theft

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Whaling matches the CEO wire transfer targeting scenario; Pretexting matches the fake recruiter phone call scenario; Shoulder surfing matches the visual observation of credential entry scenario; Diversion theft matches the rerouted physical hardware delivery scenario.
Whaling explicitly targets C-level executives (such as a Chief Executive Officer). Pretexting involves creating a believable false story or role (such as a recruiter) to manipulate the victim. Shoulder surfing relies on visually spying on credential entries or confidential displays. Diversion theft manipulates delivery routes or physical couriers to misdirect incoming or outgoing physical goods.

Adım Adım Çözüm

1
Analyze each social engineering attack term and identify its primary operating characteristic.
Whaling targets senior executives; Pretexting uses constructed narratives; Shoulder surfing uses direct visual observation; Diversion theft manipulates physical delivery logistics.
Distinguishing between target roles, media, and physical mechanisms allows accurate classification.
2
Map each term to the enterprise scenario that exhibits its specific behavioral indicator.
Whaling pairs with the CEO email; Pretexting pairs with the recruiter phone scenario; Shoulder surfing pairs with optical passcode viewing; Diversion theft pairs with altered courier paperwork.
Matching each vector to its distinct attack indicator ensures precise threat identification.

Anahtar Kavram

Social Engineering Attacks and Vectors
Soru 456Soru

An attacker contacts a remote branch manager while posing as an executive auditor from corporate headquarters. The attacker presents a fabricated narrative regarding an urgent regulatory compliance audit and persuades the branch manager to bypass standard identity verification procedures to grant temporary network credentials. Which social engineering technique was primarily utilized by the attacker to manipulate the victim?

Cevabı ve açıklamayı göster

Cevap: Pretexting

Cevap

Pretexting is the primary technique used, as the attacker relied on a detailed, fabricated scenario and false persona to manipulate the victim into bypassing procedures.
Pretexting is the practice of crafting a detailed, invented scenario (the pretext) to trick a target into disclosing information or granting unauthorized privileges. Impersonating an auditor under an urgent compliance context leverages the influence principles of authority and urgency within a pretextual narrative.

Adım Adım Çözüm

1
Analyze the attacker's primary tactic described in the scenario.
The attacker established a false persona (corporate executive auditor) and constructed a believable backstory (urgent regulatory audit).
Identifying the approach used to manipulate the target determines the attack category.
2
Evaluate the defined social engineering attack vectors.
Constructing a false narrative and impersonating an authority figure to manipulate an individual into surrendering access explicitly defines pretexting.
Social engineering techniques are distinguished by their delivery medium, narrative structure, and targeted manipulation method.

Anahtar Kavram

Pretexting in Social Engineering
Soru 457Soru

A security analyst is investigating a dual-vector social engineering campaign targeting a corporate facility. During the investigation, the analyst notes that employees received text messages prompting them to verify credentials on a spoofed portal, while physical USB flash drives labeled "Executive Salaries" were strategically dropped in the employee parking area. Which of the following social engineering attack vectors were executed during this campaign? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Smishing by delivering malicious web links through cellular text messaging; Baiting by leaving physical storage media loaded with malware in accessible areas

Cevap

The attack vectors executed in this campaign are smishing (using cellular text messages with malicious links) and baiting (strategically dropping infected physical media to exploit curiosity).
Smishing refers specifically to phishing attacks conducted over Short Message Service (SMS) text messages. Baiting involves leaving physical media, such as flash drives, in locations where victims will pick them up out of curiosity. Both mechanisms match the attack vectors described in the scenario.

Adım Adım Çözüm

1
Analyze the first incident indicator in the scenario.
Employees received SMS text messages containing links to a spoofed credential portal.
Phishing conducted via SMS text messaging is classified as smishing.
2
Analyze the second incident indicator in the scenario.
Malicious USB drives labeled with enticing titles were left in the parking area for employees to find.
Promising a tangible item or relying on curiosity via physical media drops is classified as baiting.
3
Correlate identified vectors with the options.
Smishing and baiting correctly match the scenario indicators.
Both vectors directly align with the delivery mechanisms described in the incident report.

Anahtar Kavram

Identification of Social Engineering Attack Vectors (Smishing vs. Baiting)
Soru 458Soru

An IT administrator receives an unverified request for sensitive internal network topology diagrams. When the administrator hesitates to comply, the requester claims that three senior network engineers in the department have already submitted their respective section diagrams for the ongoing audit. Reassured that colleagues have already complied, the administrator releases the requested files. Which of the following principles of influence did the attacker primarily exploit?

Cevabı ve açıklamayı göster

Cevap: Consensus

Cevap

Consensus
Consensus (or social proof) occurs when an attacker persuades a target to take an action by demonstrating or claiming that others—specifically peers or coworkers—have already done so. In this scenario, stating that senior engineers in the same department had already provided their diagrams led the target to believe compliance was standard and safe.

Adım Adım Çözüm

1
Analyze the attacker's psychological trigger described in the scenario.
The attacker persuaded the victim by stating that three peer engineers had already submitted their portion of the requested data.
Identifying the narrative device used to gain trust and compliance.
2
Map the observed psychological trigger to standard social engineering principles of influence.
Demonstrating that peers or equals have already complied defines the Consensus (or Social Proof) principle.
Matching attacker tactics against established social engineering frameworks.
3
Differentiate Consensus from related principles such as Authority, Urgency, or Intimidation.
Unlike Authority (which relies on rank) or Urgency (which relies on time pressure), Consensus relies on perceived peer validation.
Confirming the single best answer based on specific scenario details.

Anahtar Kavram

Principles of Influence - Consensus (Social Proof)
Soru 459Soru

Match each social engineering attack vector on the left to the real-world enterprise incident scenario on the right that best illustrates it.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Watering Hole Attack
Typosquatting
Vishing
Tailgating

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Watering Hole Attack matches the compromise of a frequently visited industry news portal; Typosquatting matches registering visually similar domain names; Vishing matches placing fraudulent phone calls to accounting personnel; Tailgating matches entering restricted facilities by following authorized employees closely.
Watering hole attacks target specific websites frequented by an intended victim demographic; typosquatting leverages domain name misspellings; vishing relies on voice phone calls for deception; and tailgating exploits physical proximity to enter secure areas without credentials.

Adım Adım Çözüm

1
Identify the primary mechanism of each social engineering attack vector listed.
Watering hole focuses on group web targeting, typosquatting relies on mistyped URLs, vishing uses voice telephone calls, and tailgating relies on unauthorized physical following.
Understanding the core transport vector (web, network domain, telephony, or physical access) distinguishes each attack type.
2
Map each concept to the scenario containing matching technical or physical indicators.
Mapped industry portal compromise to watering hole, fake login URL to typosquatting, executive phone call to vishing, and unbadged entry to tailgating.
Evaluating specific indicators in each scenario ensures precise alignment with the threat definition.

Anahtar Kavram

Social Engineering Attacks and Vectors
Tahmini Süre:1m 30s
Soru 460Soru

An attacker registers a domain name that closely resembles an enterprise's official login portal by altering a single character in the domain URL. The attacker uses this fraudulent domain to host a spoofed site that captures employee credentials when users accidentally mistype the legitimate web address. Which of the following social engineering attack vectors is best illustrated in this scenario?

Cevabı ve açıklamayı göster

Cevap: Typosquatting

Cevap

Typosquatting
Typosquatting (also known as URL hijacking) occurs when an attacker registers common misspellings, character omissions, or visually similar variations of a legitimate domain name to trick users who accidentally mistype the web address into visiting a fraudulent portal.

Adım Adım Çözüm

1
Analyze the attack mechanism described in the scenario.
The adversary registered a modified domain name to capitalize on user typing mistakes.
Identifying how victims arrive at the malicious site determines the attack vector.
2
Map the technique to standard social engineering attack definitions.
Exploiting misspellings or minor character variations in domain URLs is defined as typosquatting (URL hijacking).
Typosquatting specifically targets human errors during web address entry.

Anahtar Kavram

Typosquatting (URL Hijacking)
Tahmini Süre:1m 0s
ÖncekiSayfa 23 / 25Sonraki
Threats, Vulnerabilities, and Mitigations Alıştırma Soruları — CompTIA Security+ — Sayfa 23 | Examkin