PenTest+ PenTest+ Social Engineering & Physical Security 1 — Questions and Answers
Question 1: Which social engineering technique involves creating a fabricated scenario to manipulate a target into divulging sensitive information?
- Phishing
- Pretexting (Correct answer)
- Tailgating
- Dumpster diving
Correct answer: Pretexting
Pretexting involves inventing a believable fictional scenario (pretext) to manipulate targets into providing sensitive information or taking desired actions.
Question 2: What is 'vishing' as a social engineering attack vector?
- Visual phishing using convincing fake websites
- Voice phishing conducted over telephone calls to impersonate trusted entities (Correct answer)
- Video-based deepfake social engineering attacks
- Phishing attacks delivered via SMS messages
Correct answer: Voice phishing conducted over telephone calls to impersonate trusted entities
Vishing uses telephone calls where attackers impersonate banks, IT support, or government agencies to trick targets into revealing credentials or sensitive data.
Question 3: What is 'spear phishing' and how does it differ from standard phishing?
- Phishing using spear-shaped graphic elements in emails
- Targeted phishing customized with personal details about a specific individual or organization (Correct answer)
- A mass phishing campaign sent to millions of recipients at once
- Phishing that targets the fishing and maritime industry specifically
Correct answer: Targeted phishing customized with personal details about a specific individual or organization
Spear phishing uses personalized information about the victim (name, role, colleagues) to craft highly convincing, targeted deceptive messages unlike mass phishing blasts.
Question 4: Which tool is specifically designed for conducting social engineering campaigns and phishing simulations during pentests?
- Burp Suite
- Social-Engineer Toolkit (SET) (Correct answer)
- Metasploit Framework
- Aircrack-ng
Correct answer: Social-Engineer Toolkit (SET)
The Social-Engineer Toolkit (SET) is an open-source framework built specifically for social engineering attacks including phishing, credential harvesting, and payload delivery.
Question 5: Which social engineering influence principle exploits a target's sense of obligation after receiving something of value?
- Scarcity
- Reciprocity (Correct answer)
- Social proof
- Authority
Correct answer: Reciprocity
Reciprocity exploits the human tendency to feel obligated to return a favor, where attackers offer something (fake IT help, gifts) to elicit sensitive information in return.
Question 6: What does a 'quid pro quo' social engineering attack involve?
- A type of phishing email with Latin-themed lures
- Offering a service or benefit in exchange for information or system access (Correct answer)
- A SQL injection technique using Latin query syntax
- A spear phishing campaign targeting Latin American organizations
Correct answer: Offering a service or benefit in exchange for information or system access
Quid pro quo attacks trade a perceived benefit (like free IT support) for something of value from the target (credentials, access), exploiting the reciprocity principle.
Which social engineering technique involves creating a fabricated scenario to manipulate a target into divulging sensitive information?