eJPT Social Engineering Techniques 3 — Questions and Answers
Question 1: What distinguishes 'whaling' from standard spear phishing?
- Whaling uses SMS while spear phishing uses email
- Whaling targets high-level executives rather than general employees (Correct answer)
- Whaling involves physical access while spear phishing is digital
- Whaling uses malware attachments while spear phishing uses links only
Correct answer: Whaling targets high-level executives rather than general employees
Whaling specifically targets high-value executives (CEOs, CFOs) using highly customized and convincing messages.
Question 2: An attacker sends an email appearing to come from a company's CEO asking the CFO to urgently wire funds. This attack is specifically known as:
- Vishing
- Business Email Compromise (BEC) (Correct answer)
- Pharming
- Clone phishing
Correct answer: Business Email Compromise (BEC)
BEC involves impersonating executives via email to manipulate financial staff into transferring funds.
Question 3: Which of the following is an example of 'tailgating' in physical social engineering?
- Following an authorized employee through a secured door without using credentials (Correct answer)
- Calling the front desk and pretending to be IT support
- Sending a fake badge renewal email to all staff
- Leaving a USB drive labeled 'Payroll' in the lobby
Correct answer: Following an authorized employee through a secured door without using credentials
Tailgating (piggybacking) means physically following an authorized person through a secured entry point without authenticating.
Question 4: What is 'clone phishing'?
- Creating a duplicate social media profile to befriend the target
- Replicating a legitimate email and replacing its links with malicious ones (Correct answer)
- Setting up a fake wireless hotspot that mimics a real network
- Copying the target's website to harvest credentials
Correct answer: Replicating a legitimate email and replacing its links with malicious ones
Clone phishing takes a real, previously delivered email, duplicates it, and replaces legitimate links or attachments with malicious ones.
Question 5: Which psychological principle does an attacker exploit when they say 'Only 3 licenses left — act now or lose access' in a phishing email?
- Social proof
- Liking
- Scarcity (Correct answer)
- Commitment
Correct answer: Scarcity
Scarcity creates urgency by implying limited availability, pressuring the victim to act without thinking critically.
Question 6: During a red team engagement, you need to gather employee email formats. Which OSINT technique would be MOST efficient?
- Port scanning the mail server
- Using tools like Hunter.io or theHarvester to enumerate email patterns from public sources (Correct answer)
- Brute-forcing the SMTP server with common names
- Sending blank emails to guess valid addresses
Correct answer: Using tools like Hunter.io or theHarvester to enumerate email patterns from public sources
Hunter.io and theHarvester aggregate publicly available email addresses to reveal the company's email naming convention.
Question 7: What is the purpose of a 'callback' technique used in vishing attacks?
- To record the victim's voice for deepfake training
- To make the victim initiate the call so they trust the interaction more (Correct answer)
- To reroute the call through an anonymous VoIP service
- To automatically hang up and redial with a spoofed number
Correct answer: To make the victim initiate the call so they trust the interaction more
By prompting the victim to call back a number the attacker controls, the attacker gains trust since the victim feels they initiated contact.
What distinguishes 'whaling' from standard spear phishing?