312-50V13 · Question #394
Ben purchased a new smartphone and received some updates on it through the OTA method. He received two messages: one with a PIN from the network operator and another asking him to enter the PIN…
The correct answer is A. Advanced SMS phishing. This scenario describes an Advanced SMS phishing attack, where an attacker leverages legitimate-looking SMS messages to trick a user into providing a sensitive PIN, leading to compromise or abnormal device behavior.
Question
Options
- AAdvanced SMS phishing
- BBypass SSL pinning
- CPhishing
- DTap 'n ghost attack
How the community answered
(41 responses)- A83% (34)
- B2% (1)
- C5% (2)
- D10% (4)
Why each option
This scenario describes an Advanced SMS phishing attack, where an attacker leverages legitimate-looking SMS messages to trick a user into providing a sensitive PIN, leading to compromise or abnormal device behavior.
The scenario involves two SMS messages, one seemingly legitimate from the network operator and another malicious one prompting for the PIN, leading to abnormal phone behavior. This is an advanced form of SMS phishing (smishing) designed to bypass initial user skepticism by using context from a legitimate communication.
Bypass SSL pinning refers to techniques used to circumvent the security mechanism that prevents man-in-the-middle attacks on HTTPS connections to specific servers, which is not applicable to an SMS-based PIN attack.
Phishing is a general term for deceptive attempts to acquire sensitive information, but "Advanced SMS phishing" is a more specific and accurate description for this multi-step, context-aware SMS attack.
"Tap 'n ghost attack" is not a widely recognized or standard term for a mobile phone attack in cybersecurity; it seems to be a fabricated or niche term.
Concept tested: Mobile phishing (Advanced Smishing)
Source: https://www.cisa.gov/news-events/news/cisa-warns-increase-smishing-attacks
Topics
Community Discussion
No community discussion yet for this question.