By Fatskills Exam Guides Team — the exam nerds behind 28,500+ quizzes and 2.1M practice questions across 500+ global exams.
For CISSP, Security+, CEH, and Real-World Defense
Social engineering is the psychological manipulation of people into performing actions or divulging confidential information. Unlike technical attacks, it exploits human trust, curiosity, or fear—making it one of the most common and effective attack vectors.Example: The 2020 Twitter breach (where attackers used phone-based spear phishing to hijack high-profile accounts like Barack Obama’s and Elon Musk’s) resulted in a $120K Bitcoin scam and exposed flaws in employee security awareness. Social engineering is critical because humans are the weakest link in security—even the best firewalls can’t stop a tricked employee from clicking a malicious link.
An attacker sends an email to a company’s HR department posing as the IT helpdesk, requesting employees’ W-2 forms for "tax compliance." Which social engineering technique is this? A) Phishing B) Spear phishing C) Pretexting D) Baiting
✅ Correct Answer: C) PretextingExplanation: Pretexting involves creating a fabricated scenario (the "pretext") to trick the victim into disclosing information. Here, the attacker impersonates IT support to steal W-2s.
A security team wants to reduce the risk of employees falling for phishing emails. Which combination of controls is most effective? A) Firewall rules + antivirus B) MFA + email filtering + security awareness training C) Encryption + password complexity D) SIEM alerts + network segmentation
✅ Correct Answer: B) MFA + email filtering + security awareness trainingExplanation: Social engineering exploits human behavior, so layered defenses (technical + human) are critical. MFA stops credential theft, email filtering blocks malicious emails, and training reduces click rates.
Which tool would an ethical hacker use to simulate a spear phishing campaign for a penetration test? A) Metasploit B) Gophish C) Nmap D) John the Ripper
✅ Correct Answer: B) GophishExplanation: Gophish is an open-source phishing framework designed for security testing. Metasploit is for exploitation, Nmap for scanning, and John the Ripper for password cracking.
Join 4M+ learners. Unlock unlimited quizzes, wrong-answer tracking, flashcards + reminders, study guides, and 1-on-1 challenges.