A user receives a phone call from someone claiming to be from IT support, asking for their password to perform a system update. This is an example of which social engineering technique?
Trap 1: Baiting
Baiting relies on an attacker leaving a physical or digital 'bait' for the victim to discover and interact with, such as a malware-laden USB drive or a tempting 'free download' link. The victim is lured by the promise of something desirable, triggering their curiosity or greed. This scenario, involving a direct phone call without an initial enticing 'offer' to be found, does not align with the typical characteristics of a baiting attack.
Trap 2: Phishing
Phishing is a broad social engineering technique primarily executed through electronic communication, typically email or fraudulent websites, designed to trick recipients into revealing personal information or clicking malicious links. It often involves impersonating a legitimate organization to create a sense of trust or urgency. While 'vishing' is a form of phishing, the term 'phishing' alone generally refers to text-based or web-based attacks, not direct voice calls.
Trap 3: Vishing
Vishing, or voice phishing, is a social engineering attack conducted over the telephone, where attackers attempt to solicit sensitive information by impersonating trusted entities. Unlike pretexting, vishing often relies on generic, high-volume scripts that exploit fear or urgency, such as fake IRS calls or tech support scams, without necessarily developing a highly specific, tailored backstory for the individual target. The key distinction here is the lack of a deeply fabricated, individualized scenario that defines pretexting.
- A
Baiting
Why wrong: Baiting relies on an attacker leaving a physical or digital 'bait' for the victim to discover and interact with, such as a malware-laden USB drive or a tempting 'free download' link. The victim is lured by the promise of something desirable, triggering their curiosity or greed. This scenario, involving a direct phone call without an initial enticing 'offer' to be found, does not align with the typical characteristics of a baiting attack.
- B
Pretexting
Pretexting involves an attacker fabricating a believable scenario and a false identity to manipulate a victim into divulging sensitive information. The attacker creates a detailed backstory, often impersonating someone in authority or a trusted entity, to establish a sense of legitimacy and urgency. This elaborate setup is designed to overcome the victim's skepticism and directly solicit specific data, like a password, through social engineering.
- C
Phishing
Why wrong: Phishing is a broad social engineering technique primarily executed through electronic communication, typically email or fraudulent websites, designed to trick recipients into revealing personal information or clicking malicious links. It often involves impersonating a legitimate organization to create a sense of trust or urgency. While 'vishing' is a form of phishing, the term 'phishing' alone generally refers to text-based or web-based attacks, not direct voice calls.
- D
Vishing
Why wrong: Vishing, or voice phishing, is a social engineering attack conducted over the telephone, where attackers attempt to solicit sensitive information by impersonating trusted entities. Unlike pretexting, vishing often relies on generic, high-volume scripts that exploit fear or urgency, such as fake IRS calls or tech support scams, without necessarily developing a highly specific, tailored backstory for the individual target. The key distinction here is the lack of a deeply fabricated, individualized scenario that defines pretexting.