eJPT Social Engineering Techniques 5 — Questions and Answers
Question 1: Which of the following best describes a 'reverse social engineering' attack?
- The attacker pretends to be a victim to gain sympathy
- The attacker creates a problem, then poses as the solution provider to gain the target's trust (Correct answer)
- The target hacks back at the attacker using their own techniques
- The attacker uses automated tools to reverse-engineer the victim's password
Correct answer: The attacker creates a problem, then poses as the solution provider to gain the target's trust
In reverse social engineering, the attacker creates or exploits a problem and then presents themselves as the expert who can solve it, gaining trust and access.
Question 2: During a penetration test, you call a receptionist claiming to be from corporate IT and ask them to verify the 'server room door code' for a 'system audit.' The receptionist complies. Which principle was exploited?
- Scarcity
- Authority combined with urgency (Correct answer)
- Social proof
- Reciprocity
Correct answer: Authority combined with urgency
Impersonating IT authority and framing the request as urgent audit work exploits authority and urgency to bypass critical thinking.
Question 3: What is the primary goal of a 'credential harvesting' page in a phishing attack?
- To install ransomware on the victim's device
- To trick the victim into submitting their username and password to an attacker-controlled server (Correct answer)
- To redirect the victim to a legitimate site after showing ads
- To collect the victim's browser fingerprint for tracking
Correct answer: To trick the victim into submitting their username and password to an attacker-controlled server
A credential harvesting page mimics a legitimate login page and captures submitted credentials, forwarding them to the attacker.
Question 4: In a penetration test report, you document that staff accepted an unknown visitor as a legitimate contractor. Which control gap does this indicate?
- Weak password policy
- Lack of visitor management and identity verification procedures (Correct answer)
- Missing endpoint detection software
- Insufficient network segmentation
Correct answer: Lack of visitor management and identity verification procedures
Without formal visitor management and ID verification, unauthorized individuals can gain physical access through impersonation.
Question 5: An attacker sends a phishing email that appears to come from 'noreply@company-support.net' while the real domain is 'company.com.' What should a technically aware user inspect to detect this?
- The email subject line
- The sender's display name
- The full email header including the actual From address and SPF/DKIM results (Correct answer)
- The size of any email attachment
Correct answer: The full email header including the actual From address and SPF/DKIM results
Examining the full email header reveals the true sending domain and SPF/DKIM authentication results, exposing spoofed sender addresses.
Question 6: What role does 'urgency' play in most social engineering attacks?
- It ensures the victim has time to verify the request with their manager
- It pressures the victim to act quickly, bypassing normal security verification steps (Correct answer)
- It signals that the message is automated and therefore trustworthy
- It reduces the attacker's risk of being traced
Correct answer: It pressures the victim to act quickly, bypassing normal security verification steps
Urgency short-circuits the victim's rational evaluation by creating time pressure that discourages verification.
Question 7: Which of the following is a key indicator that a phone call may be a vishing attack?
- The caller speaks in a professional tone
- The caller requests sensitive information (passwords, OTPs) over the phone, claiming urgent action is needed (Correct answer)
- The caller asks to be transferred to another department
- The caller provides their full name and employee ID upfront
Correct answer: The caller requests sensitive information (passwords, OTPs) over the phone, claiming urgent action is needed
Legitimate organizations never ask for passwords or one-time codes over the phone; such requests combined with urgency are hallmarks of vishing.
Which of the following best describes a 'reverse social engineering' attack?