Threats, Vulnerabilities, and Mitigations

490 soru

Soru 481Soru

An employee at a corporate office scans their access badge to open a secured entrance door. Immediately after, an unidentified individual without a badge walks inside right behind the employee before the door closes. Which of the following social engineering attacks is best demonstrated in this scenario?

Cevabı ve açıklamayı göster

Cevap: Tailgating

Cevap

Tailgating
The scenario describes tailgating (also called piggybacking), which takes place when an unauthorized person gains physical entrance into a restricted area by closely following an authorized employee who opened the door.

Adım Adım Çözüm

1
Analyze the entry method described in the scenario
An unauthorized individual gains access into a secured facility by following immediately behind an authenticated worker.
Identifying the method of access separates physical facility vectors from digital network attack vectors.
2
Match the behavior to standard social engineering attack definitions
Following an authorized person through a secure portal without credentials defines tailgating (or piggybacking).
Tailgating relies on human courtesy or social norms to bypass physical authentication barriers.

Anahtar Kavram

Tailgating physical social engineering attack
Tahmini Süre:45s
Soru 482Soru

An employee attempting to navigate to an external vendor portal mistypes the domain name in the web browser address bar and is redirected to a fraudulent site designed to mimic the authentic login screen. Which of the following attack vectors is demonstrated in this scenario?

Cevabı ve açıklamayı göster

Cevap: Typosquatting

Cevap

Typosquatting
Typosquatting (also known as URL hijacking) occurs when threat actors register domain names that are slight misspellings of legitimate websites to capture traffic from users who make typographical errors.

Adım Adım Çözüm

1
Identify the attack mechanism presented in the scenario.
The user mistyped a legitimate domain name in the browser address bar.
The attack relies on typographical mistakes made during web navigation.
2
Match the mechanism to the correct social engineering attack term.
Registering common misspellings of popular domains to trap users is known as typosquatting (or URL hijacking).
This directly aligns with the definition of typosquatting.

Anahtar Kavram

Typosquatting (URL Hijacking)
Soru 483Soru

Match each social engineering principle of influence on the left with its corresponding enterprise attack scenario description on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Authority
Consensus
Scarcity
Urgency

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Authority matches the executive impersonation scenario; Consensus matches the claim that all other department heads submitted credentials; Scarcity matches the claim of limited remaining license slots; Urgency matches the claim of an imminent server crash within minutes.
Each principle of influence aligns with its specific psychological trigger: Authority uses hierarchy and position, Consensus relies on peer participation, Scarcity uses perceived limited availability, and Urgency creates artificial time pressure.

Adım Adım Çözüm

1
Analyze each scenario on the right to identify the psychological driver leveraged by the attacker.
The executive role exploits power (Authority); peer actions exploit social proof (Consensus); limited licenses exploit limited supply (Scarcity); short deadlines exploit time pressure (Urgency).
Social engineering attacks rely on specific psychological principles of influence to manipulate victims.
2
Pair each principle of influence on the left to its corresponding attack scenario.
Authority maps to executive demand, Consensus maps to peer compliance, Scarcity maps to limited slots, and Urgency maps to the tight time constraint.
Matching principles to their defining characteristics confirms correct identification of attack vectors.

Anahtar Kavram

Principles of Influence in Social Engineering
Tahmini Süre:1m 0s
Soru 484Soru

An organization's security team detects an unauthorized login to a corporate account. Incident analysis reveals that the compromised employee received an SMS notification on their mobile device claiming to be from the IT helpdesk, warning that their account access would be revoked unless verified immediately via a provided URL. The link directed the user to a fraudulent authentication portal where their credentials were captured. Which social engineering attack vector initiated this security incident?

Cevabı ve açıklamayı göster

Cevap: Smishing

Cevap

Smishing is the social engineering attack vector delivered through SMS text messaging.
Smishing (SMS phishing) specifically leverages Short Message Service (SMS) text messages as the vector to deliver deceptive lures and malicious links to mobile devices. In this scenario, the attack was initiated through an urgent SMS notification containing a link to a credential harvesting site.

Adım Adım Çözüm

1
Identify the communication channel used in the attack vector.
The attack initiated with an SMS text message delivered to a mobile device.
Social engineering attack classification relies on the transport medium utilized to contact the target.
2
Map the identified SMS channel to the correct Security+ attack taxonomy term.
Phishing conducted specifically over SMS text messages is defined as smishing.
Differentiation between phishing variants depends on the transport protocol (SMS = smishing, voice call = vishing, targeted email = spear phishing).

Anahtar Kavram

Social Engineering Attack Vectors and Transport Media
Tahmini Süre:1m 0s
Soru 485Soru

A field technician working at a remote facility discovers several corporate-branded USB flash drives left on tables in the facility's cafeteria. Each drive is labeled with the text "Q3 Executive Compensation & Bonus Allocations - Confidential." Driven by curiosity, the technician plugs one of the drives into a corporate network workstation to view the contents, triggering an automatic payload execution that harvests local account credentials. Which type of social engineering attack vector did the threat actor utilize in this scenario?

Cevabı ve açıklamayı göster

Cevap: Baiting

Cevap

Baiting is the social engineering vector utilized when an attacker leaves infected physical media in accessible locations, exploiting human curiosity to induce victims to insert the media into target systems.
Baiting involves leaving a malware-infected physical device (such as a USB drive) in a location where target users are likely to find it. The attacker relies on victim curiosity (heightened by enticing labels like confidential financial documents) to prompt them to connect the device to an enterprise computer.

Adım Adım Çözüm

1
Analyze the attack medium and delivery mechanism described in the scenario.
The attack relies on physical media (labeled USB flash drives) intentionally placed in a public/accessible employee area.
Identifying the medium (physical storage device vs. web browser vs. physical door) narrows down the social engineering category.
2
Evaluate the psychological psychological trigger exploited by the threat actor.
The label 'Q3 Executive Compensation' appeals directly to employee curiosity and greed.
Social engineering tactics manipulate specific human psychological factors; curiosity piqued by high-value labeled media is characteristic of baiting.
3
Match the attack indicators to the specific CompTIA Security+ social engineering taxonomy definition.
Leaving malicious hardware media for an unsuspecting victim to find and insert into a workstation defines a baiting attack.
Distinguishing baiting from watering hole or pretexting ensures accurate vector identification.

Anahtar Kavram

Baiting Attack Vector
Tahmini Süre:1m 0s
Soru 486Soru

A receptionist at an enterprise regional office receives a phone call from an individual claiming to be a technician from the building management company. The caller states that an urgent HVAC emergency requires immediate physical access to the server room key box and asks the receptionist to read the emergency access PIN code over the phone. The caller provides fake ticket numbers and references real facility manager names to build credibility. Which of the following social engineering techniques did the attacker primarily execute in this scenario?

Cevabı ve açıklamayı göster

Cevap: Pretexting

Cevap

Pretexting
Pretexting is the act of creating a believable fabricated scenario or identity (the pretext) to trick a victim into disclosing sensitive information or granting unauthorized access. In this scenario, the attacker impersonated a facilities technician and fabricated an HVAC emergency to deceive the receptionist into revealing a sensitive PIN.

Adım Adım Çözüm

1
Analyze the attack vector and communication channel in the scenario.
The attack uses direct phone communication where the adversary impersonates an authorized technician and provides fabricated context (fake ticket numbers, real employee names).
Identifying the method of contact helps narrow down the social engineering classification.
2
Evaluate the underlying psychological tactic.
The attacker creates a false background story (an emergency HVAC maintenance event) to manipulate the recipient into breaking security protocols.
Creating a fake background narrative to establish trust and trick a target is the defining characteristic of pretexting.
3
Compare the scenario against alternative social engineering definitions.
Watering hole attacks involve site compromise, baiting uses tangible enticements, and pharming uses DNS manipulation; none of these rely on direct verbal narrative fabrication.
Differentiating techniques ensures accurate categorization based on attack mechanics.

Anahtar Kavram

Pretexting in Social Engineering
Soru 487Soru

Match each social engineering attack vector or influence principle on the left with the enterprise incident scenario on the right that best demonstrates its execution.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Whaling
Shoulder Surfing
Diversion Theft
Scarcity (Influence Principle)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Whaling pairs with the scenario involving a targeted email sent directly to the CEO. Shoulder Surfing pairs with the scenario involving direct visual observation of credential entry in a cafe. Diversion Theft pairs with the scenario involving redirecting incoming physical shipments of equipment. Scarcity pairs with the scenario leveraging limited remaining trial licenses to trick staff.
Each attack vector or principle matches its operational execution: Whaling targets top executives (CEO), Shoulder Surfing relies on direct visual observation, Diversion Theft intercepts physical transit shipments, and Scarcity exploits psychological urgency built around limited remaining quantities.

Adım Adım Çözüm

1
Identify the target profile for Whaling
Recognize that Whaling specifically targets high-ranking executives like C-level leadership, matching the CEO wire transfer scenario.
Whaling is a specialized variant of spear phishing aimed at high-value targets within an organization.
2
Analyze physical observation threat vectors
Identify Shoulder Surfing as the technique where an attacker visually eavesdrops on password or credential entry in public spaces.
Direct visual observation of keyboards and screens falls directly under shoulder surfing risks.
3
Evaluate supply chain physical transport attack methods
Link Diversion Theft to the physical rerouting of incoming hardware packages and logistics couriers.
Diversion theft focuses on intercepting goods in transit by deceiving transportation personnel.
4
Evaluate psychological principles of influence
Associate Scarcity with the tactic of offering limited availability items (such as only five trial licenses) to coerce hasty victim action.
Scarcity relies on the fear of missing out due to restricted availability or strict deadlines.

Anahtar Kavram

Social Engineering Vectors and Principles of Influence
Tahmini Süre:1m 30s
Soru 488Soru

An accounts payable specialist receives an urgent email that appears to originate from the organization's Chief Financial Officer (CFO). The message references an undisclosed legal settlement and directs the specialist to immediately wire $45,000 to an external account, explicitly instructing them to bypass normal dual-authorization procedures to meet a strict deadline. Investigation reveals the message originated from an external domain registered to mimic the enterprise domain by substituting the letter 'o' with the number '0'. Which of the following attack types is best described in this scenario?

Cevabı ve açıklamayı göster

Cevap: Whaling combined with typosquatting

Cevap

Whaling combined with typosquatting
Whaling is a specialized form of spear phishing that specifically targets or impersonates senior executives (such as a CFO) to authorize high-value transactions or release sensitive data. Typosquatting (also known as URL hijacking) involves registering domain names that closely resemble legitimate domains (such as replacing the letter 'o' with the digit '0') to deceive recipients into believing the sender is authentic.

Adım Adım Çözüm

1
Analyze the target and impersonation role in the scenario
The attack impersonates high-level corporate leadership (CFO) to mandate financial transactions, which characterizes a whaling attack variant of spear phishing.
Whaling focuses on executive leadership roles or high-value targets.
2
Analyze the technical vector used to deceive the recipient
The attacker registered a fraudulent domain using character substitution ('0' for 'o') to trick users looking at sender addresses.
Typosquatting relies on subtle typographical variations of legitimate domain names.
3
Synthesize the attack elements to select the correct social engineering combination
The combination of executive impersonation (whaling) and deceptive domain registration (typosquatting) matches the scenario.
Both techniques work together to establish authority and bypass casual human verification.

Anahtar Kavram

Executive Impersonation (Whaling) and Deceptive Domain Registration (Typosquatting)
Soru 489Soru

An organization's security operations center (SOC) detects an incident where an employee received a text message on their mobile phone containing an urgent link to verify their corporate single sign-on (SSO) credentials on a fraudulent domain. Shortly after, an unknown attacker calls the IT helpdesk, posing as the employee and using previously gathered personal details to request an account recovery passcode. Which of the following social engineering vectors were directly utilized in this attack scenario? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Smishing; Vishing

Cevap

The attack scenario directly utilized smishing and vishing.
Smishing and vishing are correct because the attacker used SMS text messages containing malicious links and telephone calls impersonating an employee to execute the credential harvesting and unauthorized access attempt.

Adım Adım Çözüm

1
Analyze the SMS message vector
Identified smishing due to fraudulent text messages sent to mobile devices.
Phishing delivered via short message service (SMS) is categorized specifically as smishing.
2
Analyze the phone call and impersonation vector
Identified vishing due to deceptive telephone interaction targeting the helpdesk.
Voice-based social engineering attempts conducted over the phone constitute vishing.

Anahtar Kavram

Social Engineering Attacks and Vectors
Soru 490Soru

During a routine audit, an incident response team discovers that multiple remote employees entered their domain credentials into a web page that visually duplicated the organization's authentic single sign-on (SSO) portal. Investigation reveals that the domain name used in the attack was registered by an external third party and contained a single transposed letter relative to the official enterprise URL. Which social engineering attack vector was directly executed in this scenario?

Cevabı ve açıklamayı göster

Cevap: Typosquatting

Cevap

Typosquatting is the correct vector, as it explicitly relies on registering slight misspellings or character transpositions of legitimate domain names to trick users into visiting deceptive websites.
Typosquatting (also known as URL hijacking) occurs when an attacker registers domain names that are slight misspellings, character swaps, or variations of a legitimate domain. When users inadvertently type the wrong address or follow a link to the spoofed domain, they are presented with a fraudulent site designed to harvest sensitive information such as SSO credentials.

Adım Adım Çözüm

1
Analyze the scenario indicators
The attacker registered a look-alike domain with a transposed letter pointing to a cloned SSO landing page.
Identifying the specific mechanism used by the attacker establishes the underlying social engineering category.
2
Compare against social engineering definitions
Registering URLs that mirror legitimate corporate domains via misspellings/transpositions matches the exact definition of typosquatting (URL hijacking).
Differentiating between delivery mechanisms (email vs. phone vs. fake domain registration) ensures correct vector classification.

Anahtar Kavram

Typosquatting (URL Hijacking)
ÖncekiSayfa 25 / 25
Threats, Vulnerabilities, and Mitigations Alıştırma Soruları — CompTIA Security+ — Sayfa 25 | Examkin