Social Engineering Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Social Engineering Techniques flashcards as text
Which of the following best describes a 'reverse social engineering' attack?
Answer: The attacker creates a problem, then poses as the solution provider to gain the target's trust
In reverse social engineering, the attacker creates or exploits a problem and then presents themselves as the expert who can solve it, gaining trust and access.
During a penetration test, you call a receptionist claiming to be from corporate IT and ask them to verify the 'server room door code' for a 'system audit.' The receptionist complies. Which principle was exploited?
Answer: Authority combined with urgency
Impersonating IT authority and framing the request as urgent audit work exploits authority and urgency to bypass critical thinking.
What is the primary goal of a 'credential harvesting' page in a phishing attack?
Answer: To trick the victim into submitting their username and password to an attacker-controlled server
A credential harvesting page mimics a legitimate login page and captures submitted credentials, forwarding them to the attacker.
In a penetration test report, you document that staff accepted an unknown visitor as a legitimate contractor. Which control gap does this indicate?
Answer: Lack of visitor management and identity verification procedures
Without formal visitor management and ID verification, unauthorized individuals can gain physical access through impersonation.
An attacker sends a phishing email that appears to come from 'noreply@company-support.net' while the real domain is 'company.com.' What should a technically aware user inspect to detect this?
Answer: The full email header including the actual From address and SPF/DKIM results
Examining the full email header reveals the true sending domain and SPF/DKIM authentication results, exposing spoofed sender addresses.
What role does 'urgency' play in most social engineering attacks?
Answer: It pressures the victim to act quickly, bypassing normal security verification steps
Urgency short-circuits the victim's rational evaluation by creating time pressure that discourages verification.
Which of the following is a key indicator that a phone call may be a vishing attack?
Answer: The caller requests sensitive information (passwords, OTPs) over the phone, claiming urgent action is needed
Legitimate organizations never ask for passwords or one-time codes over the phone; such requests combined with urgency are hallmarks of vishing.