A security awareness training designer wants to create a module specifically about GenAI-enabled social engineering. Which scenario best illustrates a 'novel' GenAI-enabled attack that would NOT have been feasible before 2022?
- A.A phone call from someone claiming to be the IRS demanding immediate gift card payment; synthetic voice is watermarked by law in the US and EU, and telecom carriers strip unwatermarked synthetic audio from calls in transit
- B.A social engineering call where the attacker claims to be a new IT contractor needing temporary access credentials; C2PA content credentials are embedded in the pixel data itself, surviving crops, re-encodes and screenshots, which lets any platform verify provenance
- C.A real-time video call where the caller's face is replaced by a convincing deepfake of a known executive, combined with a cloned voice, allowing an attacker to conduct a live interactive impersonation conversation
- D.A phishing email with a spoofed domain name impersonating the company's IT department
Why C is correct