Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A new employee receives an email that appears to be from the CEO, urgently requesting their login credentials to resolve a critical system issue. The email contains a link to a fake login page that looks identical to the company's internal portal. This is a classic example of which common security threat?
- AMalware
- BDenial of Service (DoS)
- CSocial Engineering
- DInsider Threat
Show answer & explanationAnswer & explanation
Correct answer: C. Social Engineering
The scenario describes an attacker manipulating an employee through psychological trickery (impersonating the CEO, creating urgency) to divulge sensitive information (login credentials). This is the definition of social engineering, specifically phishing.
Why the other options are wrong
- A. Malware is malicious software; this scenario describes a human-based attack to gain credentials, not software infection directly.
- B. DoS attacks prevent access to services; this attack aims to gain access, not deny it.
- D. An insider threat comes from within the organization; this is an external attacker using deception.
Social Engineering
The psychological manipulation of people into performing actions or divulging confidential information.
- Exploits human trust, curiosity, or fear.
- Common forms include phishing, pretexting, baiting, quid pro quo.
- Often a precursor to other attacks like malware delivery.
Memory trick: Social Engineering: The art of tricking people, not computers.