โ† All EJPT Flashcard Decks

Social Engineering Techniques Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Social Engineering Techniques flashcards as text
  1. An attacker poses as a fire marshal and walks through an office taking photos of workstations under the guise of a 'safety inspection.' This is best described as:

    Answer: Impersonation-based physical social engineering

    Impersonation involves assuming a false identity (e.g., fire marshal) to gain physical access and gather intelligence.

  2. Which tool is commonly used during penetration tests to generate convincing phishing emails and credential-harvesting pages?

    Answer: Social-Engineer Toolkit (SET)

    The Social-Engineer Toolkit (SET) automates phishing campaigns and credential harvesting site cloning for authorized engagements.

  3. What does 'OSINT' stand for and how does it relate to social engineering?

    Answer: Open Source Intelligence โ€” used to gather target information from public sources before an attack

    OSINT (Open Source Intelligence) involves collecting publicly available information to build detailed profiles for targeted social engineering attacks.

  4. A red team attacker recovers printed emails and internal memos from a company's recycling bin. This technique is called:

    Answer: Dumpster diving

    Dumpster diving involves searching through discarded materials to find sensitive information useful for crafting attacks.

  5. Which of the following BEST mitigates the risk of social engineering attacks targeting employees?

    Answer: Regular security awareness training with simulated phishing exercises

    Security awareness training combined with simulated phishing teaches employees to recognize and report social engineering attempts.

  6. What is 'elicitation' in social engineering?

    Answer: Extracting sensitive information through seemingly casual conversation without the target realizing they're being manipulated

    Elicitation uses natural conversation techniques (flattery, false statements, volunteering information) to make targets reveal sensitive data without suspicion.

  7. An attacker registers the domain 'paypa1.com' to deceive victims into entering PayPal credentials. This technique is called:

    Answer: Typosquatting

    Typosquatting registers domains with slight misspellings or character substitutions to catch users who mistype legitimate URLs.

Social Engineering Techniques Flashcards โ€” EJPT Study Cards with Answers