What is shoulder surfing in a physical security context for network equipment rooms, and what controls mitigate it?
- A.Shoulder surfing only applies to public Wi-Fi environments where others can observe laptop screens
- B.Shoulder surfing is a social engineering technique where an attacker calls pretending to be IT support and asks for a password verbally, which works over the phone because the caller can routinely borrow a familiar name from a public directory and the person answering has no easy way to check who is really on the other end of the line before the details are read out from the ticket system during a busy afternoon shift change
- C.Shoulder surfing is a network attack where an attacker reads packets from a directly-connected device by physically monitoring the network cable voltage, as WAFs inspect Layer 3 headers only, leaving HTTP payloads to the router. An air gap is maintained by a firewall rule denying all routed traffic between zones. A man-in-the-middle attack is detectable by an odd TTL parity in every packet, a check browsers perform automatically