Social Engineering and Physical Security Flashcards
6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Social Engineering and Physical Security flashcards as text
What is spear phishing and how does it differ from regular phishing?
Answer: Targeted phishing aimed at specific individuals using personalized information, versus mass generic emails
Spear phishing targets specific individuals or organizations with highly personalized messages using researched information (name, position, projects), making them much more convincing and dangerous than generic phishing campaigns.
What is pretexting in social engineering?
Answer: Creating a fabricated scenario to manipulate a victim into providing information or access
Pretexting involves creating a convincing fabricated scenario (impersonating IT support, a vendor, or authority figure) to build trust and manipulate the target into revealing sensitive information or granting access.
What is tailgating (piggybacking) in physical security?
Answer: Following an authorized person through a secured door without presenting credentials
Tailgating is a physical social engineering technique where an unauthorized person follows closely behind an authorized individual through a secured entrance, bypassing access controls through social pressure or stealth.
What is a watering hole attack?
Answer: Compromising a website frequently visited by the target group to infect their systems
A watering hole attack identifies websites commonly visited by the target organization's employees, compromises those websites with malware, and waits for targets to visit and become infected.
What is shoulder surfing and how can it be prevented?
Answer: Observing someone's screen or keyboard to steal credentials; prevented with privacy screens and awareness
Shoulder surfing involves visually observing someone entering passwords, PINs, or viewing sensitive information on their screen. Prevention includes privacy screen filters, awareness training, and using biometric authentication.
What is vishing and how does it differ from phishing?
Answer: Voice-based phishing using phone calls to extract information, versus email-based phishing
Vishing (voice phishing) uses phone calls or voicemail to impersonate trusted entities (banks, tech support, government) and manipulate victims into revealing sensitive information, as opposed to email-based phishing.