GCFA · Question #27
An executive in your company reports odd behavior on her PDA. After investigation you discover that a trusted device is actually copying data off the PDA. The executive tells you that the behavior…
The correct answer is B. Bluesnarfing. Bluesnarfing is a Bluetooth attack where an attacker gains unauthorized access to a victim device's data after the victim accepts a connection or file from a malicious source.
Question
An executive in your company reports odd behavior on her PDA. After investigation you discover that a trusted device is actually copying data off the PDA. The executive tells you that the behavior started shortly after accepting an e-business card from an unknown person. What type of attack is this?
Options
- ASession Hijacking
- BBluesnarfing
- CPDA Hijacking
- DPrivilege Escalation
How the community answered
(23 responses)- A13% (3)
- B74% (17)
- C9% (2)
- D4% (1)
Why each option
Bluesnarfing is a Bluetooth attack where an attacker gains unauthorized access to a victim device's data after the victim accepts a connection or file from a malicious source.
Session hijacking involves taking over an already-authenticated network session over TCP/IP and does not apply to Bluetooth pairing exploits on a PDA.
Bluesnarfing is the unauthorized access to or theft of data from a Bluetooth-enabled device by exploiting Bluetooth protocols such as the Object Push Profile. The scenario describes a trusted device copying data off the PDA immediately after the executive accepted a Bluetooth e-business card (vCard) from an unknown person, which is the classic bluesnarfing vector used to establish unauthorized pairing and extract data.
PDA Hijacking is not a recognized or standardized security attack category and does not describe the specific Bluetooth-based mechanism in this scenario.
Privilege escalation involves gaining elevated permissions on a system the attacker already has access to, not stealing data through a Bluetooth connection from an external device.
Concept tested: Bluetooth bluesnarfing attack via device pairing
Source: https://www.cisa.gov/sites/default/files/publications/Bluetooth_Security_Guide.pdf
Topics
Community Discussion
No community discussion yet for this question.