A city help-desk clerk resets a privileged password after a caller claims to be the CIO and cites an urgent council meeting. Enterprise Security shows no exploit payload, no C2 session, and no stolen token. Which term correctly classifies this attack?
Select an answer to reveal the explanation.
Short Explanation
This one never touched a packet. Someone played CIO on the phone, leaned on urgency, and the help desk handed over a reset — that is social engineering, psychology as the exploit. If ES is quiet on malware and C2, do not go hunting a buffer overflow that is not there.
Full Explanation
Social engineering is psychological manipulation that causes a person to take an unsafe action, such as resetting a privileged civic account. Splunk Certified Cybersecurity Defense Analyst objective 2.2 treats it as its own attack term, distinct from packet-level exploits, supply-chain tampering, denial-of-service, and command-and-control. When Enterprise Security shows no payload, beacon, or stolen token, the evidence still supports a human-targeted attack. Civic SOCs should classify the event on that behavior and pull help-desk and identity logs, not invent a host exploit to match a more familiar notable.