Social Engineering Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Social Engineering Techniques flashcards as text
An attacker calls a help desk posing as a new IT vendor and asks staff to reset a user's password 'for testing purposes.' What social engineering principle is primarily being exploited?
Answer: Authority
The attacker exploits authority by impersonating a vendor with perceived technical authority over IT systems.
Which of the following best describes a 'watering hole' attack in the context of social engineering?
Answer: Compromising a website frequently visited by the target group
A watering hole attack compromises a website the target group regularly visits, so victims are infected when they browse it.
During a penetration test, you discover that employees freely share internal org-chart details with strangers on LinkedIn. Which OSINT-based social engineering threat does this enable?
Answer: Spear phishing with personalized context
Org-chart data enables crafting highly personalized spear phishing emails that reference real names and roles.
What is 'pretexting' in social engineering?
Answer: Creating a fabricated scenario to manipulate a target into revealing information
Pretexting involves inventing a believable scenario (pretext) to trick the victim into complying with a request.
An attacker sends an SMS claiming the target's bank account is locked and provides a link to 'verify identity.' This is an example of:
Answer: Smishing
Smishing (SMS phishing) uses text messages to lure victims into revealing credentials or clicking malicious links.
Which defense is MOST effective against baiting attacks that use infected USB drives?
Answer: Disabling AutoRun and enforcing USB device restrictions via policy
Disabling AutoRun and blocking unauthorized USB devices via endpoint policy prevents automatic execution of malicious payloads.
In social engineering reconnaissance, what information gathered from social media is MOST useful for crafting a convincing phishing pretext?
Answer: The target's recent work events, colleagues' names, and projects
Recent work events and colleague names allow attackers to craft believable, context-aware pretexts that bypass suspicion.