バージニア州アーリントンにある防衛関連企業が、従業員の人間による操作への感受性をテストするため、社内意識向上演習を開始した。評価中、外部の採用コンサルタントを装った人物が、近隣の業界交流イベントで数名のエンジニアに何気なく話しかけ始めた。複数回の会話を通して、その人物は徐々に話題を現在の研究イニシアチブ、開発スケジュール、社内プロジェクトのコードネームへと誘導していった。認証情報やシステムアクセスを直接要求することはなかった。代わりに、非公式な会話の中に巧妙に仕込まれた質問を通して、情報は段階的に入手された。このシナリオで最も正確に示されているソーシャルエンジニアリングの手法はどれか?
正解:C
The technique demonstrated is Elicitation. CEH social engineering coverage explains elicitation as the art of drawing out information from a target through conversation without making direct or obviously suspicious requests. The attacker carefully guides dialogue so the victim voluntarily reveals sensitive details, often believing the discussion is normal, harmless, or professionally relevant. That is exactly what happens here: the person poses as a recruitment consultant, builds rapport through multiple informal interactions, and gradually obtains information about research, timelines, and internal code names. No credentials are requested and no overt trade or reward is offered, so this is not quid pro quo. It is also not baiting, which typically relies on an enticing object or opportunity, nor a honey trap, which usually involves romantic or intimate manipulation.
CEH materials emphasize that elicitation is especially dangerous because the victim often does not realize that the attacker's questions are strategically sequenced to extract valuable intelligence piece by piece. The gradual, conversational, non-confrontational harvesting of sensitive project details in this scenario is the defining pattern of elicitation.