← All EJPT Flashcard Decks

Social Engineering Techniques Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Social Engineering Techniques flashcards as text
  1. What distinguishes 'whaling' from standard spear phishing?

    Answer: Whaling targets high-level executives rather than general employees

    Whaling specifically targets high-value executives (CEOs, CFOs) using highly customized and convincing messages.

  2. An attacker sends an email appearing to come from a company's CEO asking the CFO to urgently wire funds. This attack is specifically known as:

    Answer: Business Email Compromise (BEC)

    BEC involves impersonating executives via email to manipulate financial staff into transferring funds.

  3. Which of the following is an example of 'tailgating' in physical social engineering?

    Answer: Following an authorized employee through a secured door without using credentials

    Tailgating (piggybacking) means physically following an authorized person through a secured entry point without authenticating.

  4. What is 'clone phishing'?

    Answer: Replicating a legitimate email and replacing its links with malicious ones

    Clone phishing takes a real, previously delivered email, duplicates it, and replaces legitimate links or attachments with malicious ones.

  5. Which psychological principle does an attacker exploit when they say 'Only 3 licenses left — act now or lose access' in a phishing email?

    Answer: Scarcity

    Scarcity creates urgency by implying limited availability, pressuring the victim to act without thinking critically.

  6. During a red team engagement, you need to gather employee email formats. Which OSINT technique would be MOST efficient?

    Answer: Using tools like Hunter.io or theHarvester to enumerate email patterns from public sources

    Hunter.io and theHarvester aggregate publicly available email addresses to reveal the company's email naming convention.

  7. What is the purpose of a 'callback' technique used in vishing attacks?

    Answer: To make the victim initiate the call so they trust the interaction more

    By prompting the victim to call back a number the attacker controls, the attacker gains trust since the victim feels they initiated contact.