200-201 Question 150
Select 3An employee at a financial institution receives an email from what appears to be their IT department, requesting them to reset their password by clicking on a link. The email includes a sense of urgency, claiming that their account will be locked if they do not comply within 24 hours. Upon examination, the link redirects to a fake login page. What type(s) of social engineering attack does this scenario describe?
- A
Phishing
- B
Impersonation
- C
Baiting
- D
Pretexting
- E
Quid pro quo
Show answer and explanation
Correct answers: A, B, D
Explanation
This scenario combines multiple social engineering techniques. The attacker uses phishing to send a fake email with a malicious link, impersonates the IT department to gain the victim's trust, and uses pretexting to invent an urgent situation to manipulate the victim into acting without suspicion. Understanding these tactics is crucial for defending against social engineering attacks.
- A. Correct.
Phishing is correct because the email tries to trick the employee into clicking a malicious link to steal credentials, which is a hallmark of phishing attacks.
- B. Correct.
Impersonation is correct because the attacker is pretending to be the IT department to gain the employee's trust.
- C. Incorrect.
Baiting is incorrect because there is no indication of an enticing offer or reward used to lure the target into taking action.
- D. Correct.
Pretexting is correct because the attacker creates a fabricated scenario (urgent account lockout) to manipulate the victim into revealing sensitive information.
- E. Incorrect.
Quid pro quo is incorrect because there is no exchange of services or promises made to the victim in this scenario.