An independent cybersecurity audit of a corporate office identified three distinct security incidents involving human manipulation.
Identify and describe the specific social engineering technique illustrated in each of the following scenarios:
An attacker modified a local DNS server so that employees entering the correct URL for their internal HR portal were silently redirected to an identical fraudulent website designed to harvest login details.
An attacker telephoned the administrative desk pretending to be an external IT technician working on an urgent server upgrade, successfully fabricating a scenario to convince the receptionist to share temporary network passwords.
An attacker stood in a crowded office corridor, covertly watching a network administrator as they typed the master passcode into the physical keypad of a restricted server room.