An AI safety researcher argues that 'GenAI dramatically lowers the barrier to entry for social engineering attacks.' Which specific capability BEST supports this claim?
- A.A. GenAI can automatically break encryption, allowing attackers to read intercepted communications
- B.D. GenAI can predict which employees are most susceptible to social engineering based on their social media profiles
- C.C. GenAI makes it easier to exploit software vulnerabilities because it can generate exploit code
- D.B. GenAI enables attackers without social engineering skills, language fluency, or domain expertise to generate highly convincing, context-rich deceptive content that previously required skilled operators
Why D is correct
The barrier-lowering argument centers on skill substitution: previously, effective spear-phishing required human operators with language skills, contextual knowledge, and social intelligence. GenAI substitutes for these skills - a low-skill attacker can prompt an LLM to craft a convincing, personalized, contextually appropriate deceptive message in seconds. This democratizes sophisticated social engineering and scales it to mass attacks.
Know someone studying for AI Security Fundamentals? Send them this one.