1. National Institute of Standards and Technology (NIST). (2021). NIST Glossary - Social Engineering. CSRC. Retrieved from https://csrc.nist.gov/glossary/term/socialengineering.
Reference Point: The glossary defines social engineering as "The act of deceiving an individual into revealing sensitive information
obtaining unauthorized access
or committing fraud by associating with the individual to gain confidence and trust." This directly supports the correct answer. The glossary also provides distinct definitions for brute-force
man-in-the-middle
and pharming that align with the explanations for the incorrect options.
2. Grassi
P. A.
Garcia
M. E.
& Fenton
J. L. (2017). NIST Special Publication 800-63-3: Digital Identity Guidelines. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63-3
Reference Point: Section 5.2.2
"Threats
" discusses social engineering as a primary method attackers use to trick legitimate users into disclosing authenticators or other private information
which is precisely what occurs in the scenario.
3. Saltzer
J. H.
& Kaashoek
M. F. (2009). Principles of Computer System Design: An Introduction. Morgan Kaufmann. (Material often used in MIT OpenCourseWare
e.g.
6.033 Computer System Engineering).
Reference Point: Chapter 11
"Security and Protection
" Section 11.2.2
"Attacks
" describes social engineering as a non-technical attack that persuades or tricks an authorized user into revealing information or taking a specific action. The use of a forged ID is a form of persuasion and trickery.