Social engineering techniques and physical security testing methods tested on the CompTIA PenTest+ exam.
29 cards · basic cards · AI-written, checked twice. Edit anything.
- What is phishing in the context of social engineering?
- A mass-distribution attack sending fraudulent emails or messages to trick recipients into revealing credentials, clicking malicious links, or opening infected attachments.
- How does spear phishing differ from standard phishing?
- Spear phishing targets specific individuals or organizations with customized messages based on personal information gathered beforehand, rather than mass-distribution attacks.
- What is whaling in social engineering?
- A targeted phishing attack focused on senior executives or high-value targets, using customized messages that reference their position or authority.
- Define vishing as a social engineering technique.
- A voice-based phishing attack using phone calls or VoIP to impersonate a trusted entity and manipulate a target into disclosing sensitive information.
- What is smishing?
- A phishing attack delivered through SMS text messages, typically containing a malicious link or spoofed sender to deceive the recipient into taking harmful action.
- Explain pretexting as a social engineering method.
- Creating a fabricated scenario or assumed identity to build trust with a target and extract confidential information or gain unauthorized access.
- What is baiting in social engineering?
- Offering something enticing, such as a free USB drive or gift card, containing malware or tracking software, to trick a target into taking a harmful action.
- Define tailgating in the context of physical security testing.
- Following an authorized person through a secure door or controlled entry point without using a valid credential, exploiting their physical presence to gain unauthorized access.
- What is shoulder surfing?
- Observing someone entering credentials, PIN numbers, or sensitive information by looking over their shoulder or from a nearby vantage point.
- Explain dumpster diving in social engineering.
- Searching through an organization's trash or recycling bins to find discarded documents, files, or hardware containing sensitive information or credentials.
- What is the authority principle in social engineering?
- Exploiting a person's tendency to comply with perceived authority figures by impersonating someone in a position of power or responsibility.
- How does the urgency principle work in social engineering attacks?
- Creating artificial time pressure or crisis to force a target to bypass normal security procedures and make hasty decisions without verification.
- Explain the scarcity principle used in social engineering.
- Making something appear limited or exclusive to motivate immediate action from a target, such as claiming a special offer expires soon.
- What is the likability principle in social engineering?
- Building rapport and establishing a sense of friendship or shared interests with a target to increase their willingness to comply with requests.
- Why is target profiling important in social engineering testing?
- Gathering information about targets' roles, responsibilities, and personal details enables creating more convincing pretexts and selecting appropriate attack vectors.