Identifying USB Baiting Social Engineering Attacks
An employee finds a USB flash drive labeled "Salary Info" in an office parking lot. The employee picks up the USB flash drive, goes into the office, and plugs it into a laptop. Later, a technician inspects the laptop and realizes it has been compromised by malware. Which of the following types of social engineering attacks has occurred?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the ability to distinguish between physical and remote social engineering attacks, specifically identifying 'baiting' when physical devices like USB drives are used as the lure.
This question examines the specific social engineering technique where malicious actors leave infected physical media to compromise systems. It establishes that leaving a labeled USB drive in a public place is classified as baiting.
Candidates often confuse this with pretexting or tailgating because they involve human interaction or deception, but those do not involve leaving a physical lure for the victim to initiate the connection.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Baiting is a social engineering attack that uses the promise of a benefit or reward to entice a victim into a trap that steals their data or compromises their systems. In this scenario, the attacker left a USB flash drive labeled "Salary Info" in a parking lot. The enticing label triggers curiosity, causing the employee to plug it into a laptop, which results in malware infection. This specific subtype is often called "USB dropping" or "autoloader" attack.Why the Other Options Are Wrong
Smishing (SMS phishing) involves fraudulent text messages sent via mobile phones, not physical hardware found in a parking lot. Tailgating occurs when an unauthorized person follows an authorized person into a restricted area, relying on physical proximity rather than a digital lure. Pretexting involves creating a fabricated scenario (a pretext) to engage the victim and extract information, typically through phone calls or impersonation, rather than leaving a physical object.Community Comment Notes
The community consensus strongly supports Baiting, with multiple commenters noting that this is also known as "USB dropping" or "usb baiting." As salah112 noted, the key is the use of a physical device left in a location likely to be found by the target. Jared77 further clarified that the attacker hopes the person will plug it in out of curiosity due to the labeling.Exam Strategy
When analyzing social engineering questions, look for the primary vector of delivery. If physical media (USBs, CDs) or tangible rewards are involved, think 'Baiting'. If it's a phone call or fake email, think 'Phishing', 'Vishing', or 'Smishing'. If it involves impersonation to gain trust, think 'Pretexting'.
Frequently Asked Questions
What is the difference between baiting and pretexting?
Baiting uses a physical lure (like a USB) to trick the victim into connecting it. Pretexting relies on a fabricated story or identity to manipulate the victim into revealing information.
Is plugging in a found USB always considered baiting?
Yes, if the device was intentionally left by an attacker to exploit curiosity. It is a subset of baiting often called 'USB dropping'.