← All EJPT Flashcard Decks

Social Engineering Techniques Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Social Engineering Techniques flashcards as text
  1. Which of the following best describes a 'reverse social engineering' attack?

    Answer: The attacker creates a problem, then poses as the solution provider to gain the target's trust

    In reverse social engineering, the attacker creates or exploits a problem and then presents themselves as the expert who can solve it, gaining trust and access.

  2. During a penetration test, you call a receptionist claiming to be from corporate IT and ask them to verify the 'server room door code' for a 'system audit.' The receptionist complies. Which principle was exploited?

    Answer: Authority combined with urgency

    Impersonating IT authority and framing the request as urgent audit work exploits authority and urgency to bypass critical thinking.

  3. What is the primary goal of a 'credential harvesting' page in a phishing attack?

    Answer: To trick the victim into submitting their username and password to an attacker-controlled server

    A credential harvesting page mimics a legitimate login page and captures submitted credentials, forwarding them to the attacker.

  4. In a penetration test report, you document that staff accepted an unknown visitor as a legitimate contractor. Which control gap does this indicate?

    Answer: Lack of visitor management and identity verification procedures

    Without formal visitor management and ID verification, unauthorized individuals can gain physical access through impersonation.

  5. An attacker sends a phishing email that appears to come from 'noreply@company-support.net' while the real domain is 'company.com.' What should a technically aware user inspect to detect this?

    Answer: The full email header including the actual From address and SPF/DKIM results

    Examining the full email header reveals the true sending domain and SPF/DKIM authentication results, exposing spoofed sender addresses.

  6. What role does 'urgency' play in most social engineering attacks?

    Answer: It pressures the victim to act quickly, bypassing normal security verification steps

    Urgency short-circuits the victim's rational evaluation by creating time pressure that discourages verification.

  7. Which of the following is a key indicator that a phone call may be a vishing attack?

    Answer: The caller requests sensitive information (passwords, OTPs) over the phone, claiming urgent action is needed

    Legitimate organizations never ask for passwords or one-time codes over the phone; such requests combined with urgency are hallmarks of vishing.