GSLC · Question #556
In which of the following social engineering attacks does an attacker first damage any part of the target's equipment and then advertise himself as an authorized person who can help fix the problem.
The correct answer is D. Reverse social engineering attack. Reverse social engineering is an attack where the attacker first creates a problem, then positions themselves as the trusted solution - causing the victim to initiate contact and voluntarily grant access.
Question
In which of the following social engineering attacks does an attacker first damage any part of the target's equipment and then advertise himself as an authorized person who can help fix the problem.
Options
- AImpersonation attack
- BIn person attack
- CImportant user posing attack
- DReverse social engineering attack
How the community answered
(26 responses)- A8% (2)
- B4% (1)
- D88% (23)
Why each option
Reverse social engineering is an attack where the attacker first creates a problem, then positions themselves as the trusted solution - causing the victim to initiate contact and voluntarily grant access.
An impersonation attack involves directly pretending to be a legitimate user, authority figure, or vendor without first engineering a situation that compels the victim to seek help.
In-person attack describes a delivery method or vector for social engineering, not a distinct attack technique with a specific sequence of steps like reverse social engineering.
An important user posing attack (VIP impersonation) involves the attacker claiming to be a high-ranking individual to pressure victims into compliance, and does not involve first creating a technical problem to exploit.
In a reverse social engineering attack, the attacker deliberately sabotages or damages the target's equipment to manufacture a problem the victim urgently needs resolved. The attacker then advertises themselves as an authorized technician or support person, causing the victim to reach out and willingly provide access - a more effective approach than unsolicited contact because the victim perceives the attacker as helpful rather than threatening.
Concept tested: Reverse social engineering attack technique and sequence
Source: https://csrc.nist.gov/glossary/term/social_engineering
Topics
Community Discussion
No community discussion yet for this question.