Module 9: Social Engineering

Detailed Explanations for Questions 226-250


Q226. You are the senior manager in the IT department for your company. What is the most cost-effective way to prevent social engineering attacks?

  • A. Install HIDS.
  • B. Ensure that all patches are up-to-date.
  • C. Monitor and control all email activity.
  • D. Implement security awareness training. ✓

Why D is correct: Security awareness training is the most cost-effective defense against social engineering because these attacks target human psychology, not technical vulnerabilities. Training educates employees to recognize manipulation tactics (pretexting, phishing, urgency, authority impersonation), verify requests, and follow security procedures. Training can be delivered internally at minimal cost and scales to all employees.

Why others are incorrect:

  • A: HIDS (Host-based Intrusion Detection System) detects technical attacks on endpoints, not human manipulation attempts
  • B: Patching addresses software vulnerabilities, not the human element that social engineering exploits
  • C: Email monitoring might catch some phishing attempts but doesn’t address phone-based, in-person, or other social engineering vectors, and requires significant resources

Q227. You are a passenger in an airport terminal. You glance across the terminal and notice a man peering over the shoulder of a young woman as she uses her tablet. What do you think he is doing?

  • A. Wardriving
  • B. Shoulder surfing ✓
  • C. War shouldering
  • D. Shoulder jacking

Why B is correct: Shoulder surfing is the act of visually observing someone entering sensitive information (passwords, PINs, personal data) by looking over their shoulder or from a nearby position. This is a passive, low-tech attack that requires no special equipment and is common in public spaces.

Why others are incorrect:

  • A: Wardriving involves searching for wireless networks while driving, not observing individuals
  • C: “War shouldering” is not a recognized security term
  • D: “Shoulder jacking” is not a recognized security term

Q228. What type of social engineering attack uses SMS (text) messages to communicate with the victim?

  • A. Smishing ✓
  • B. Vishing
  • C. Phishing
  • D. Kishing

Why A is correct: Smishing (SMS + phishing) specifically uses text messages to deliver malicious links, request sensitive information, or trick victims into taking harmful actions. The SMS channel is effective because users often trust text messages and may click links without the scrutiny they might apply to email.

Why others are incorrect:

  • B: Vishing (voice + phishing) uses phone calls, not text messages
  • C: Phishing typically refers to email-based attacks, though it’s the umbrella term
  • D: “Kishing” is not a recognized social engineering term

Q229. An email contains a link with the subject line “Congratulations on your cruise!” and is sent to the finance person at a company. The email instructs the reader to click a hyperlink to claim the cruise. When the link is clicked, the reader is presented with a series of questions within an online form, such as name, Social Security number, and date of birth. What type of attack would this be considered?

  • A. Email phishing
  • B. Spear phishing ✓
  • C. Social engineering
  • D. Identity theft

Why B is correct: Spear phishing is a targeted phishing attack directed at specific individuals or roles (like a finance person) with personalized content designed to increase success rates. The email’s specific targeting of a finance person with a tailored lure (“Congratulations on your cruise!”) indicates spear phishing rather than broad, untargeted phishing.

Why others are incorrect:

  • A: Email phishing is too generic; while this is delivered via email, the targeted nature makes “spear phishing” the more accurate classification
  • C: Social engineering is the broad category; spear phishing is the specific technique being used
  • D: Identity theft may be the ultimate goal, but the question asks about the attack method, not the potential outcome

Q230. During an annual security training course you are facilitating, you place a call to another employee picked randomly who is not part of the training class. In this call, you state that you work in the help desk department and request their password in order to reset an account you noticed is locked. What risk are you demonstrating?

  • A. Social engineering ✓
  • B. Weak passwords
  • C. Malware being installed by workers
  • D. Spam emails circulating the office

Why A is correct: This scenario demonstrates social engineering through pretexting—creating a fabricated scenario (being from help desk, needing to reset a locked account) to manipulate the victim into divulging sensitive information (their password). The attacker exploits trust in internal support roles and urgency to bypass normal security procedures.

Why others are incorrect:

  • B: While weak passwords are a security issue, this scenario focuses on the manipulation technique, not password strength
  • C: No malware installation is described in this scenario
  • D: This is a phone-based attack, not email-based spam

Q231. You call into the city manager’s office, claiming to be a part of the help desk team. You ask the clerk for her username and password to install the latest Microsoft Office suite. What type of attack are you conducting?

  • A. Social engineering ✓
  • B. Piggybacking
  • C. Masquerading
  • D. Tailgating

Why A is correct: This is social engineering via pretexting—impersonating a trusted role (help desk) with a plausible reason (software installation) to trick the victim into revealing credentials. The attack exploits human trust and authority rather than technical vulnerabilities.

Why others are incorrect:

  • B: Piggybacking is a physical security attack where an unauthorized person follows an authorized person into a secure area
  • C: Masquerading is a broader term for impersonation, but doesn’t specifically describe the credential-harvesting social engineering technique
  • D: Tailgating is similar to piggybacking—a physical access attack, not a phone-based credential request

Q232. An attacker is dressed as a postal worker. Holding some large boxes, he follows a group of workers to make his drop-off in the back of the facility. What is the attacker trying to conduct?

  • A. Phishing
  • B. Sliding
  • C. Piggybacking ✓
  • D. Shimming

Why C is correct: Piggybacking is a physical social engineering attack where an unauthorized person gains entry to a secure area by following authorized personnel, often exploiting courtesy (someone holding the door) or distraction. The attacker’s disguise (postal worker) and props (boxes) are designed to appear legitimate and elicit cooperation.

Why others are incorrect:

  • A: Phishing uses electronic communications (email, SMS) to trick victims, not physical access attempts
  • B: “Sliding” is not a recognized security term
  • D: “Shimming” typically refers to a type of hardware attack or a thin metal tool, not a physical access technique

Q233. As a black hat, you forge an identification badge and dress in clothes associated with a maintenance worker. You attempt to follow other maintenance personnel as they enter the power grid facility. What are you attempting to do?

  • A. Piggybacking
  • B. Social engineering
  • C. Tailgating ✓
  • D. Impersonating

Why C is correct: Tailgating is very similar to piggybacking but typically implies the attacker enters without the authorized person’s knowledge or consent (vs. piggybacking where the authorized person may knowingly hold the door). Forging credentials and following authorized personnel into a secure facility is classic tailgating.

Why others are incorrect:

  • A: Piggybacking often implies the authorized person knowingly allows entry; tailgating is more about stealthy entry
  • B: While this is a form of social engineering, “tailgating” is the more specific and accurate term for this physical access technique
  • D: Impersonating describes the disguise but not the specific access technique being attempted

Q234. What is the act of looking over the shoulder of a victim to capture the information being displayed on their machine?

  • A. Piggybacking
  • B. Impersonation
  • C. Shoulder surfing ✓
  • D. Shoulder peering

Why C is correct: Shoulder surfing is the recognized term for visually observing someone’s screen, keyboard, or documents to capture sensitive information like passwords, PINs, or confidential data. It’s a simple, low-tech attack effective in public or semi-public spaces.

Why others are incorrect:

  • A: Piggybacking is a physical access attack, not a visual observation
  • B: Impersonation involves pretending to be someone else, not observing their actions
  • D: “Shoulder peering” is not the standard term; “shoulder surfing” is the accepted terminology

Q235. Which option describes the act of rummaging through trash to find important data?

  • A. Dumpster swimming
  • B. Social engineering
  • C. Dumpster collection
  • D. Dumpster diving ✓

Why D is correct: Dumpster diving is the standard term for searching through discarded trash, recycling, or documents to find sensitive information that was improperly disposed of (account statements, network diagrams, employee lists, etc.). This is a form of passive reconnaissance.

Why others are incorrect:

  • A: “Dumpster swimming” is not a recognized term
  • B: While dumpster diving can be part of social engineering reconnaissance, it’s a specific technique with its own name
  • C: “Dumpster collection” refers to waste management services, not information gathering

Q236. Which of the following activities describes the act of a person rummaging through a trash container looking for sensitive information?

  • A. Trash jumping
  • B. Dumpster party
  • C. Trash diving
  • D. Dumpster diving ✓

Why D is correct: Dumpster diving is the universally recognized term in security for searching discarded materials for sensitive information. The term is well-established in both security literature and common usage.

Why others are incorrect:

  • A, B, C: None of these are recognized security terms; they appear to be made-up variations

Q237. What type of attack is the adversary conducting in the following diagram? (Good guy typing password, Bad guy looking over shoulder)

  • A. Man-in-the-middle attack
  • B. Shoulder surfing ✓
  • C. Passive reconnaissance
  • D. Foot inactive surveillance

Why B is correct: The diagram depicts one person observing another entering credentials, which is the definition of shoulder surfing—a direct visual attack to capture sensitive information.

Why others are incorrect:

  • A: Man-in-the-middle involves intercepting communications between two parties, not direct visual observation
  • C: While shoulder surfing could be considered passive reconnaissance, it’s a specific technique with its own name
  • D: “Foot inactive surveillance” is not a recognized security term

Q238. What is an advantage of a phone call over a phishing email?

  • A. You are able to go into more detail with pretexting using a conversation. ✓
  • B. Phishing attacks are rarely successful.
  • C. Not everyone has email, but everyone has a phone.
  • D. Pretexting requires the use of a phone.

Why A is correct: Phone calls allow attackers to engage in dynamic, interactive conversations where they can adapt their pretext in real-time, build rapport, apply pressure, and respond to victim questions—making the social engineering attempt more convincing and effective than a static email.

Why others are incorrect:

  • B: Phishing attacks can be highly successful; this is not an advantage of phone calls
  • C: While phone penetration may be high in some demographics, email is also nearly universal in business contexts
  • D: Pretexting can be conducted via email, text, or in person; it doesn’t require a phone

Q239. Why might you use a phone call for a social engineering attack over a phishing message?

  • A. Phishing attacks don’t guarantee success.
  • B. Pretexting only works over the phone.
  • C. Pretexting is more detailed on the phone.
  • D. More people have phones than email. ✓

Why D is correct: Phone numbers may have broader reach than email addresses in certain target populations (e.g., general public vs. corporate employees). Additionally, people may be less suspicious of phone calls than emails, especially if the caller appears authoritative.

Why others are incorrect:

  • A: While true, this doesn’t specifically explain why phone calls would be preferred
  • B: Pretexting works via multiple channels; it’s not phone-exclusive
  • C: Pretexting can be detailed in any medium; the advantage is interactivity, not detail level

Q240. What type of attack might you use if you want to collect credentials by calling a user?

  • A. Spam
  • B. Social engineering ✓
  • C. Whaling
  • D. Manipulation

Why B is correct: Calling a user to collect credentials is social engineering via vishing (voice phishing) or pretexting. The attacker creates a plausible scenario to manipulate the victim into revealing sensitive information.

Why others are incorrect:

  • A: Spam refers to unsolicited bulk messages, not targeted credential harvesting via phone
  • C: Whaling specifically targets high-value individuals (executives); the question doesn’t specify the target’s role
  • D: Manipulation is too broad; social engineering is the specific security term for this technique

Q241. As part of an assessment on an organization you working for, you decide to conduct a social engineering attack to gather credentials that you will use later. What type of attack would be the most efficient if you wanted to get credentials from an administrator?

  • A. Man-in-the-middle
  • B. Pharming
  • C. Spear phishing ✓
  • D. Phishing

Why C is correct: Spear phishing is the most efficient for targeting specific high-value individuals like administrators because it uses personalized, researched content that increases the likelihood of success. Administrators are trained to recognize generic phishing, so tailored attacks are more effective.

Why others are incorrect:

  • A: Man-in-the-middle requires network access and technical setup; it’s not efficient for initial credential gathering
  • B: Pharming involves DNS manipulation to redirect users to fake sites; it’s complex and not targeted at specific individuals
  • D: Generic phishing has low success rates against trained personnel like administrators

Q242. You are a system administrator for a law firm. You are informed that a few users are indicating that they are receiving email messages from the help desk asking for their username and password to confirm ticket creation. They indicate they have not opened any tickets with the help desk. What is likely going on?

  • A. Smishing
  • B. Phishing ✓
  • C. Vishing
  • D. Fishing

Why B is correct: This describes a classic phishing attack: fraudulent emails impersonating a trusted internal entity (help desk) requesting sensitive credentials. The mismatch between the email claim and actual user activity is a red flag indicating phishing.

Why others are incorrect:

  • A: Smishing uses SMS/text messages, not email
  • C: Vishing uses voice calls, not email
  • D: “Fishing” is not a security term; it’s likely a distractor

Q243. A city clerk received an email providing details about transferring money to a supplier. The email provides a URL asking for credentials for city bank accounts so payments can be made to the supplier. The email address does not match the one used by the supplier. What may be the issue here?

  • A. Spear phishing ✓
  • B. Theft
  • C. Whaling
  • D. Tradecraft

Why A is correct: This is spear phishing: a targeted email attack impersonating a legitimate business partner (supplier) with a plausible business request (money transfer) designed to harvest banking credentials. The mismatched email address is a key indicator of fraud.

Why others are incorrect:

  • B: Theft is the potential outcome, not the attack method
  • C: Whaling targets high-level executives; a city clerk may not qualify as a “whale” target
  • D: Tradecraft refers to intelligence gathering techniques, not this specific email-based attack

Q244. You receive a text message providing a link to a website with a message indicating you have vulnerabilities in your phone that need to be checked. What sort of an attack is this likely to be?

  • A. Spear phishing
  • B. Vishing
  • C. Smishing ✓
  • D. Whaling

Why C is correct: This is smishing: a phishing attack delivered via SMS/text message. The message creates urgency (“vulnerabilities that need to be checked”) and includes a malicious link, which are classic smishing tactics.

Why others are incorrect:

  • A: Spear phishing is typically email-based and highly targeted; this appears to be a broader SMS campaign
  • B: Vishing uses voice calls, not text messages
  • D: Whaling targets high-value individuals with highly personalized attacks; this appears to be a generic SMS

Q245. What method is used to send a malicious URL using a text message?

  • A. Smishing ✓
  • B. Vishing
  • C. Phishing
  • D. Whaling

Why A is correct: Smishing specifically refers to phishing attacks delivered via SMS/text messages, which commonly include malicious URLs designed to steal credentials or install malware.

Why others are incorrect:

  • B: Vishing uses voice calls
  • C: Phishing typically refers to email-based attacks, though smishing is a subset
  • D: Whaling is highly targeted phishing against executives, not defined by the delivery method

Q246. What type of social engineering attack uses SMS (text) messages to communicate with the victim?

  • A. Smishing ✓
  • B. Vishing
  • C. Phishing
  • D. Kishing

Why A is correct: Smishing (SMS phishing) is the specific term for social engineering attacks delivered via text messages.

Why others are incorrect:

  • B: Vishing uses voice calls
  • C: Phishing is the broader category; smishing is the SMS-specific variant
  • D: “Kishing” is not a recognized term

Q247. Which of the following tools could you use to fully automate a social engineering attack, like sending out a phishing campaign?

  • A. Nmap
  • B. Metasploit
  • C. Setoolkit ✓
  • D. Aircrack

Why C is correct: The Social Engineer Toolkit (SET) is specifically designed to automate social engineering attacks, including phishing campaigns, credential harvesting sites, and payload generation. It integrates with Metasploit but focuses on the social engineering aspect.

Why others are incorrect:

  • A: Nmap is a port scanner and network discovery tool
  • B: Metasploit is an exploitation framework; while SET uses Metasploit modules, Metasploit itself doesn’t automate social engineering campaigns
  • D: Aircrack is a wireless security auditing tool

Q248. What tool could you use to fully automate a social engineering attack, like sending out a phishing campaign?

  • A. Nmap
  • B. Metasploit
  • C. Setoolkit ✓
  • D. Aircrack

(Duplicate of Q247 – same explanation applies)


Q249. Which of the following best describes steganography?

  • A. A symmetric encryption algorithm
  • B. Allowing the public to use your private key
  • C. Hiding information within a picture or concealing it in an audio format ✓
  • D. Encrypting data using transposition and substitution

Why C is correct: Steganography is the practice of concealing information within another file or medium (images, audio, video) so that the existence of the hidden data is not apparent. Unlike encryption, which makes data unreadable, steganography makes data invisible.

Why others are incorrect:

  • A: Steganography is not an encryption algorithm; it’s a concealment technique
  • B: This describes public key cryptography, not steganography
  • D: This describes classical encryption techniques (like substitution ciphers), not steganography

Q250. Which of the following best describes steganography?

  • A. A symmetric encryption algorithm
  • B. Allowing the public to use your private key
  • C. Hiding information within a picture or concealing it in an audio format ✓
  • D. Encrypting data using transposition and substitution

(Duplicate of Q249 – same explanation applies)


Key Takeaways for Module 9: Social Engineering

  1. Human Factor is Key: Social engineering targets psychology, not technology. Training and awareness are the most effective defenses.
  2. Attack Variants by Channel:
    • Phishing: Email-based
    • Smishing: SMS/text-based
    • Vishing: Voice/phone-based
    • Spear phishing: Targeted, personalized attacks
    • Whaling: Targeted at executives/high-value targets
  3. Physical Social Engineering:
    • Shoulder surfing: Visual observation of credentials
    • Tailgating/Piggybacking: Unauthorized physical access by following authorized personnel
    • Dumpster diving: Searching discarded materials for sensitive information
  4. Pretexting: Creating a fabricated scenario to manipulate victims into divulging information or performing actions.
  5. Automation Tools: SET (Social Engineer Toolkit) automates phishing and other social engineering campaigns.
  6. Steganography: Concealing data within other files (images, audio) rather than encrypting it.
  7. Defense Strategy: Combine technical controls (email filtering, MFA) with human controls (training, verification procedures, clear policies).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top