ALISON Social Engineering & Human Factor Security 2 — Questions and Answers
Question 1: What is 'baiting' as a social engineering technique?
- Sending threatening emails to cause panic
- Leaving infected USB drives or media in public places for victims to find (Correct answer)
- Calling victims and pretending to be tech support
- Monitoring a target's physical surroundings
Correct answer: Leaving infected USB drives or media in public places for victims to find
Baiting lures victims by leaving malware-laden physical media (like USB drives) where curious individuals will pick them up and insert them into computers.
Question 2: Which term describes a highly targeted phishing attack aimed at a specific individual or organization?
- Clone phishing
- Spear phishing (Correct answer)
- Whaling
- Pharming
Correct answer: Spear phishing
Spear phishing targets specific individuals using personalized information to make the attack more convincing than generic phishing campaigns.
Question 3: What is 'whaling' in the context of social engineering?
- Mass phishing campaigns targeting thousands of users
- Spear phishing attacks targeting senior executives or high-profile individuals (Correct answer)
- Attacks against maritime or shipping industry networks
- Using large botnets to deliver phishing emails
Correct answer: Spear phishing attacks targeting senior executives or high-profile individuals
Whaling targets 'big fish' such as CEOs, CFOs, and other executives, leveraging their authority and access to high-value systems.
Question 4: What countermeasure best protects against phishing attacks in an organization?
- Blocking all email attachments
- Implementing multi-factor authentication and employee phishing simulations (Correct answer)
- Disabling all outbound internet traffic
- Using only phone-based communications
Correct answer: Implementing multi-factor authentication and employee phishing simulations
Combining MFA (to limit damage if credentials are stolen) with simulated phishing training significantly reduces organizational phishing risk.
Question 5: What does 'quid pro quo' mean as a social engineering tactic?
- Monitoring network traffic for sensitive data
- Offering a service or benefit in exchange for information or access (Correct answer)
- Sending fake invoices to financial departments
- Impersonating a vendor during a physical visit
Correct answer: Offering a service or benefit in exchange for information or access
In quid pro quo attacks, the attacker offers something valuable (like IT help) in exchange for the victim providing credentials or access.
Question 6: Which behavior is the best indicator that an employee has been effectively trained against social engineering?
- They never click on any email links
- They verify unexpected requests through an out-of-band communication channel (Correct answer)
- They immediately forward suspicious emails to all colleagues
- They disable email on their workstation when away
Correct answer: They verify unexpected requests through an out-of-band communication channel
Verifying requests via a separate, trusted channel (like calling the requester directly on a known number) defeats most social engineering attempts.
What is 'baiting' as a social engineering technique?