About this interactive
The base version of this activity sorts by channel — email, phone, text, door. This one does not let you do that, because the eight bins here overlap on channel and separate on mechanism instead. The question to ask each scenario is not how did it arrive, it is what is the attacker actually relying on to make this work. Answer that and the bin follows. Start with the hardest pair, because it is the one that decides whether you have understood the rule. Two of these scenarios are phone calls in which the attacker claims to be someone they are not, and they land in different bins. An attacker posing as an IT auditor to get the helpdesk to reset a privileged account is Pretexting. A caller claiming to be Microsoft Support and asking for remote access is Vishing. Both involve a phone. Both involve a lie about identity. The difference is what carries the attack. In the auditor call, the fabricated role is the whole weapon: helpdesks are built to serve authorized staff, and an auditor is precisely the kind of person a helpdesk is trained not to obstruct. Strip the invented identity out and nothing remains — there is no attack. That is what pretexting names, and it is why the same fabricated-auditor script works over email, in person, or on the phone. In the Microsoft Support call, the invented identity is thin and generic; the attack runs on the live voice itself — the urgency, the pressure, the fact that a real human is talking you through granting access in real time, which a text or an email cannot do. Vishing names the channel because the channel is doing the work. So: if removing the phone kills the attack, it is vishing. If removing the invented role kills the attack, it is pretexting. The new-contractor scenario is pretexting for the same reason as the auditor — the plausible-newcomer role is what makes the credential request sound routine, and the request would work through any medium. Smishing gets no such argument, and that is deliberate: it is here as the fixed point. Both text-message items are unambiguous, so if you find yourself hesitating over them you have started overthinking the exercise rather than reading it. A link in an SMS claiming your bank account is locked, and an SMS about a failed parcel delivery, are the two most common smishing lures in the world. Baiting is where the second real distinction lives, and it is with quid pro quo. Both offer the victim something. Baiting leaves the offer lying there and waits — the USB drive labelled Q3 Payroll Data on a desk works on curiosity, and the pirated game bundling a RAT works on the desire for something free. The attacker never interacts with the victim at all. Quid pro quo is a transaction between two people, in real time, with an explicit trade: help for credentials. The printer-jam offer and the IT tech offering to fix a slow computer are both someone standing in front of a user proposing an exchange. Bait is left; a quid pro quo is negotiated. Note that the torrented game has no physical object in it, which catches people who have memorized baiting as the USB drive attack. The medium is irrelevant; the lure is the technique. Tailgating covers both physical-entry scenarios, and one of them deserves its finer name. The food-delivery uniform following an employee through a badge-controlled door is tailgating in the strict sense — the attacker exploits the door being open without the employee ever agreeing to anything. Someone holding the door for an attacker carrying a laptop bag is technically piggybacking, because the authorized person consented; they were deceived into a courtesy rather than bypassed. That term is in the vocabulary for this set, and it is worth knowing, but CompTIA's exam objectives fold both under tailgating, which is why both items sort there. The laptop bag matters for the same reason the uniform does: props manufacture the belonging that makes holding the door feel obviously correct. Shoulder surfing is the only technique here in which the attacker never communicates with the victim, and that is its whole identity. Reading an email login over someone's shoulder in a coffee shop and watching a PIN entered at an ATM from across the aisle involve no lie, no offer, no message and no door — just observation. This is what separates it from pretexting, which needs a story, and from tailgating, which needs the victim's movement through a controlled point. The ATM item is worth pausing on: from across the aisle is not shoulder-level proximity, and the technique is named for a posture it does not actually require. Distance is not the test. Direct observation of information as it is entered is the test, which is why the same category covers a telephoto lens and a camera on a ceiling. Whaling is the bin that most often gets missed, because it looks like spear phishing and is a subtype of it. Every whaling attack is a spear phishing attack; the reverse does not hold. The discriminator is only the seniority of the target. Both items here name their target explicitly — a CEO and a CTO — and that is not incidental scenario colour, it is the answer. The reason the distinction earns its own word is that the consequences differ in kind rather than degree. Executives can authorize wire transfers, waive controls, and instruct staff who will not question them, so a single success yields an outcome no ordinary compromised account can produce. The CEO item is a good illustration of the effort that justifies the term: travel plans, board member names and a spoofed CFO address all had to be researched first, which means reconnaissance preceded the email. The CTO item, referencing an acquisition to trigger a wire transfer, is the pattern usually filed as business email compromise — the same attack seen from the loss side rather than the technique side. If a targeted email arrives at a developer or an accounts-payable clerk, it is spear phishing. Escalate the target to the C-suite and it is whaling. One habit is worth carrying out of this activity. Several of these scenarios genuinely contain more than one technique — the uniform in the tailgating item is impersonation, the auditor pretext is delivered by voice, the whaling email is spear phishing. Real attacks chain techniques, and an exam question that offered every true label would have no answer. What is being tested, here and on the exam, is the ability to name the mechanism the attack depends on rather than every mechanism it touches. Ask what happens if you remove each element in turn; the one whose removal collapses the attack is the technique.