200-201 Question 151
Single answerA cybersecurity analyst receives a report that an employee was tricked into revealing their login credentials after interacting with a chatbot on a fake company website. The chatbot convincingly posed as the company’s IT support and requested the employee’s information to resolve a 'critical account issue.' What type of social engineering attack does this scenario represent?
- A
Phishing
- B
Pretexting
- C
Baiting
- D
Tailgating
Show answer and explanation
Correct answer: B
Explanation
The scenario describes a social engineering attack where a fake IT support chatbot used a fabricated scenario to convince an employee to share their credentials. This aligns with pretexting, a type of social engineering attack where the attacker creates a believable context to manipulate the victim into revealing sensitive information.
- A. Incorrect.
Phishing typically involves sending fraudulent communications, such as emails, designed to trick individuals into revealing sensitive information. While this scenario involves deception, the use of a chatbot aligns more with pretexting.
- B. Correct.
Pretexting involves creating a fabricated scenario to manipulate a victim into divulging confidential information. In this case, the fake IT support chatbot created a false context (critical account issue) to extract login credentials.
- C. Incorrect.
Baiting involves offering something enticing, such as free software or gifts, to trick a victim into compromising their systems or sharing sensitive information. The scenario presented does not involve any form of bait or incentive.
- D. Incorrect.
Tailgating refers to unauthorized physical access to a secured area by following someone with authorized access. This is unrelated to the scenario, which involves online deception.