An organization's helpdesk reports that users are receiving calls from someone claiming to be IT support asking them to reveal their passwords or run remote access tools. What type of attack is this?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because calls from someone impersonating IT support to obtain credentials or access is vishing (voice phishing), a social engineering technique using phone pretexting to manipulate users into revealing information or taking harmful actions. A is wrong because spear phishing uses targeted email, not phone calls.
Full explanation below image
Full Explanation
B is correct because calls from someone impersonating IT support to obtain credentials or access is vishing (voice phishing), a social engineering technique using phone pretexting to manipulate users into revealing information or taking harmful actions. A is wrong because spear phishing uses targeted email, not phone calls. C is wrong because a watering hole attack compromises websites frequented by the target, not phone interactions. D is wrong because a supply chain attack compromises vendor software or hardware; this is a direct social engineering call, not a supply chain vector.