Exercise 2: Why IT Impersonation Is a Direct Threat to Support Technicians — Possible Solution ==================================================================== WHAT THIS CHAPTER SAYS ------------------------------ Per this chapter, IT impersonation is "perhaps the most direct threat to a support technician specifically, since it targets the exact trust relationship coworkers have with the support desk itself." THE TRUST RELATIONSHIP BEING EXPLOITED ------------------------------ Coworkers are trained, correctly, to trust IT and treat its requests as legitimate by default - IT is the group that's supposed to ask for things like temporary access changes, security-related actions, or account details. That default trust exists for good operational reasons; the entire support relationship depends on people not having to independently verify every routine IT request. WHY THAT MAKES IT A THREAT AIMED AT SUPPORT SPECIFICALLY ------------------------------ Every other impersonation example in this chapter (an executive, a vendor) borrows trust the target already has toward some other role. IT impersonation is different: it borrows trust in the support function itself - the exact relationship this whole course exists to protect. An attacker impersonating IT isn't just exploiting a random employee's credulity; they're exploiting the specific credibility this course's own reader either has, or extends to, the support role. WHY THIS IS ALSO A THREAT COMING FROM THE OTHER DIRECTION ------------------------------ It cuts both ways: a support technician might receive a call from someone impersonating IT (a peer, a supervisor) asking them to bypass a step, exploiting technician-to-technician trust the same way it exploits employee-to-IT trust generally. WHY THIS WORKS AS AN ANSWER ------------------------------ It states the chapter's own reasoning (trust in the support role being the exact thing exploited), explains why that's different from the other impersonation examples (which borrow trust in an unrelated role), and explains why that makes it a threat aimed at this course's own reader specifically, not employees in general.