200-201 · Question #274
An employee received an email from a colleague's address asking for the password for the domain controller. The employee noticed a missing letter within the sender's address. What does this incident…
The correct answer is D. social engineering. This incident describes a social engineering attack, specifically phishing, where an attacker impersonates a trusted source with a subtly altered email address to trick a user into divulging sensitive information.
Question
An employee received an email from a colleague's address asking for the password for the domain controller. The employee noticed a missing letter within the sender's address. What does this incident describe?
Options
- Abrute-force attack
- Binsider attack
- Cshoulder surfing
- Dsocial engineering
How the community answered
(35 responses)- A3% (1)
- B6% (2)
- C3% (1)
- D89% (31)
Why each option
This incident describes a social engineering attack, specifically phishing, where an attacker impersonates a trusted source with a subtly altered email address to trick a user into divulging sensitive information.
A brute-force attack involves systematically trying many passwords or passphrases in an attempt to guess correctly, which is a technical attack and not what is described by an email requesting credentials.
An insider attack involves a current or former employee, contractor, or business partner with legitimate access maliciously exploiting that access. Here, the attack originates from an external party impersonating an insider, indicated by the altered sender's address.
Shoulder surfing is a physical attack where an attacker directly observes a person entering sensitive information, such as passwords, by looking over their shoulder.
This scenario is a classic example of a social engineering attack, specifically phishing. The attacker impersonates a trusted colleague using a slightly altered email address (typosquatting) and creates a sense of urgency or authority to trick the employee into divulging sensitive information like a password for the domain controller, leveraging human trust and manipulation.
Concept tested: Phishing and social engineering
Source: https://www.cisa.gov/news-events/news/what-social-engineering
Topics
Community Discussion
No community discussion yet for this question.