Identifying USB Baiting Social Engineering Attacks

Answer Correct answer: B — Leaving an infected USB drive labeled with enticing information in a public place to trigger curiosity and infect a system is a classic example of baiting.

An employee finds a USB flash drive labeled "Salary Info" in an office parking lot. The employee picks up the USB flash drive, goes into the office, and plugs it into a laptop. Later, a technician inspects the laptop and realizes it has been compromised by malware. Which of the following types of social engineering attacks has occurred?

  1. Smishing
  2. Baiting Correct Answer
  3. Tailgating
  4. Pretexting

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the ability to distinguish between physical and remote social engineering attacks, specifically identifying 'baiting' when physical devices like USB drives are used as the lure.

This question examines the specific social engineering technique where malicious actors leave infected physical media to compromise systems. It establishes that leaving a labeled USB drive in a public place is classified as baiting.

Candidates often confuse this with pretexting or tailgating because they involve human interaction or deception, but those do not involve leaving a physical lure for the victim to initiate the connection.

Community Discussion (5 comments)

shady23 👍 1 Selected: B
B. Baiting
salah112 👍 3 Selected: B
B. Baiting In this scenario, the social engineering attack that has occurred is "Baiting." Baiting involves leaving a physical device, such as a USB flash drive, in a location where it is likely to be found by the target. The device is labeled in a way to entice the victim to plug it into their computer. Once plugged in, the device may contain malware or other malicious software that compromises the victim's system.
ganymede 👍 2 Selected: B
B. Baiting Also called usb baiting, or usb dropping.
Jared77 👍 2 Selected: B
USB Baiting: Leaving infected USB drives in a location where the target is likely to find them, hoping that the person will plug the USB drive into their computer out of curiosity.
Hs1208 👍 1 Selected: B
The device is typically labeled with enticing or intriguing information to bait the victim into using it.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Baiting is a social engineering attack that uses the promise of a benefit or reward to entice a victim into a trap that steals their data or compromises their systems. In this scenario, the attacker left a USB flash drive labeled "Salary Info" in a parking lot. The enticing label triggers curiosity, causing the employee to plug it into a laptop, which results in malware infection. This specific subtype is often called "USB dropping" or "autoloader" attack.

Why the Other Options Are Wrong

Smishing (SMS phishing) involves fraudulent text messages sent via mobile phones, not physical hardware found in a parking lot. Tailgating occurs when an unauthorized person follows an authorized person into a restricted area, relying on physical proximity rather than a digital lure. Pretexting involves creating a fabricated scenario (a pretext) to engage the victim and extract information, typically through phone calls or impersonation, rather than leaving a physical object.

Community Comment Notes

The community consensus strongly supports Baiting, with multiple commenters noting that this is also known as "USB dropping" or "usb baiting." As salah112 noted, the key is the use of a physical device left in a location likely to be found by the target. Jared77 further clarified that the attacker hopes the person will plug it in out of curiosity due to the labeling.

Exam Strategy

When analyzing social engineering questions, look for the primary vector of delivery. If physical media (USBs, CDs) or tangible rewards are involved, think 'Baiting'. If it's a phone call or fake email, think 'Phishing', 'Vishing', or 'Smishing'. If it involves impersonation to gain trust, think 'Pretexting'.

Frequently Asked Questions

What is the difference between baiting and pretexting?

Baiting uses a physical lure (like a USB) to trick the victim into connecting it. Pretexting relies on a fabricated story or identity to manipulate the victim into revealing information.

Is plugging in a found USB always considered baiting?

Yes, if the device was intentionally left by an attacker to exploit curiosity. It is a subset of baiting often called 'USB dropping'.

Related Analysis

← Back to SY0-601 Study Guide