You are the instructor conducting the security awareness training of your company. You are giving examples of social engineering attacks, which of the following is the best example of a user’s behavior that might lead to a threat scenario that the threat source has the lowest costs to collect information about system configurations?
A. Post job positions on online job portals
B. Share photos on social media
C. Explore an unknown USB dongle on computers
D. Share emails with colleagues

My suggested answer is A. Post job positions on online job portals.

Baiting and Phishing

Both creating phishing emails and leaving an infected USB dongle as a baiter take much effort and costs. Attackers typically have to create phishing emails and bogus servers for phishing and buy and prepare a USB dongle with malicious software and control and command servers.

Job Positions

Job Positions_Configurations


Sharing Photos

Sharing photos, e.g., family, office, or school photos, disclose your privacy, biological characteristics, kids, office settings, surroundings, posters, and so forth. However, it may not disclose system configurations directly.

It may hinder physical security because of the disclosure of the office layout and surroundings. Your photo can be used to train AI models for facial recognition. In an Agile workspace, as the following photo shows, the situation is getting worse if photos are shared publicly.


Source: AgileForAll



