Ethical Hacking Social Engineering 2 — Questions and Answers
Question 1: What is a 'watering hole attack'?
- Infecting websites frequently visited by the target organization (Correct answer)
- Poisoning a company's water supply
- Sending phishing emails to HR staff
- Installing keyloggers on shared computers
Correct answer: Infecting websites frequently visited by the target organization
A watering hole attack compromises websites that a target group regularly visits, infecting visitors with malware when they browse the compromised site.
Question 2: Which psychological principle does an attacker exploit when claiming 'Only 3 spots left — act now!' in a phishing email?
- Social proof
- Authority
- Scarcity (Correct answer)
- Reciprocity
Correct answer: Scarcity
Scarcity exploits the fear of missing out (FOMO) by creating urgency, pressuring targets to act quickly without carefully evaluating the legitimacy of the request.
Question 3: What is 'smishing'?
- Phishing via social media direct messages
- Phishing via SMS text messages (Correct answer)
- Phishing using fake email signatures
- Phishing targeting senior management
Correct answer: Phishing via SMS text messages
Smishing uses SMS text messages to deliver phishing links or request sensitive information, often impersonating banks, delivery services, or government agencies.
Question 4: Which concept describes the tendency to comply with someone perceived as an authority figure?
- Liking
- Consensus
- Authority (Correct answer)
- Commitment
Correct answer: Authority
Authority bias causes people to comply with requests from individuals perceived as experts or in positions of power, making impersonation of executives or IT staff highly effective.
Question 5: What is 'shoulder surfing' in social engineering?
- Intercepting Wi-Fi traffic in public places
- Physically observing a target's screen or keyboard to steal credentials (Correct answer)
- Cloning RFID badges at close range
- Dumpster diving for sensitive documents
Correct answer: Physically observing a target's screen or keyboard to steal credentials
Shoulder surfing involves physically observing a person entering credentials or sensitive information, typically in public places like coffee shops or airports.
Question 6: A penetration tester conducting a social engineering assessment sends an email appearing to be from IT support asking employees to click a link and verify credentials. What attack is this?
- Whaling
- Credential harvesting phishing (Correct answer)
- Vishing
- Business Email Compromise
Correct answer: Credential harvesting phishing
Credential harvesting phishing creates a fake login page linked from a phishing email to capture usernames and passwords entered by deceived victims.
What is a 'watering hole attack'?