eJPT Social Engineering Techniques 2 — Questions and Answers
Question 1: An attacker calls a help desk posing as a new IT vendor and asks staff to reset a user's password 'for testing purposes.' What social engineering principle is primarily being exploited?
- Reciprocity
- Authority (Correct answer)
- Scarcity
- Social proof
Correct answer: Authority
The attacker exploits authority by impersonating a vendor with perceived technical authority over IT systems.
Question 2: Which of the following best describes a 'watering hole' attack in the context of social engineering?
- Sending phishing emails to a large group of random users
- Compromising a website frequently visited by the target group (Correct answer)
- Calling employees and pretending to be HR
- Leaving malware-laden USB drives in a parking lot
Correct answer: Compromising a website frequently visited by the target group
A watering hole attack compromises a website the target group regularly visits, so victims are infected when they browse it.
Question 3: During a penetration test, you discover that employees freely share internal org-chart details with strangers on LinkedIn. Which OSINT-based social engineering threat does this enable?
- Vishing targeting random numbers
- Spear phishing with personalized context (Correct answer)
- Pharming via DNS poisoning
- Smishing via bulk SMS
Correct answer: Spear phishing with personalized context
Org-chart data enables crafting highly personalized spear phishing emails that reference real names and roles.
Question 4: What is 'pretexting' in social engineering?
- Sending a forged email that mimics a trusted sender
- Creating a fabricated scenario to manipulate a target into revealing information (Correct answer)
- Installing keyloggers on a target's machine
- Exploiting a software vulnerability to gain access
Correct answer: Creating a fabricated scenario to manipulate a target into revealing information
Pretexting involves inventing a believable scenario (pretext) to trick the victim into complying with a request.
Question 5: An attacker sends an SMS claiming the target's bank account is locked and provides a link to 'verify identity.' This is an example of:
- Vishing
- Smishing (Correct answer)
- Spear phishing
- Whaling
Correct answer: Smishing
Smishing (SMS phishing) uses text messages to lure victims into revealing credentials or clicking malicious links.
Question 6: Which defense is MOST effective against baiting attacks that use infected USB drives?
- Installing antivirus on all workstations only
- Disabling AutoRun and enforcing USB device restrictions via policy (Correct answer)
- Training users to scan USB drives before opening files
- Encrypting all USB drives found in common areas
Correct answer: Disabling AutoRun and enforcing USB device restrictions via policy
Disabling AutoRun and blocking unauthorized USB devices via endpoint policy prevents automatic execution of malicious payloads.
Question 7: In social engineering reconnaissance, what information gathered from social media is MOST useful for crafting a convincing phishing pretext?
- The target's IP address
- The target's recent work events, colleagues' names, and projects (Correct answer)
- The target's MAC address
- The target's browser history
Correct answer: The target's recent work events, colleagues' names, and projects
Recent work events and colleague names allow attackers to craft believable, context-aware pretexts that bypass suspicion.
An attacker calls a help desk posing as a new IT vendor and asks staff to reset a user's password 'for testing purposes.' What social engineering principle is primarily being exploited?