Lesson 02 - Group 3: Social Engineering

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/17

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:06 PM on 7/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

18 Terms

1
New cards
Social engineering
Manipulating people to obtain information or gain unauthorized access, sometimes described as “hacking the human.”
2
New cards
What are the two main purposes of social engineering?
Reconnaissance or eliciting information, and intrusion or gaining unauthorized access.
3
New cards
What are examples of human-vector attacks?
Persuading a user to run a malicious file, soliciting information from a help desk, or gaining physical access to install a monitoring device.
4
New cards
Impersonation
Pretending to be someone else.
5
New cards
What approaches may be used during impersonation?
Persuasion, consensus, liking, coercion, threats, and urgency.
6
New cards
Pretexting
Using a convincing scenario and supporting details to make a false identity or request appear legitimate.
7
New cards
How does pretexting support impersonation?
The attacker may obtain or spoof information that supports the claimed identity.
8
New cards
Phishing
Tricking a target into using a malicious resource by spoofing legitimate communications or websites.
9
New cards
Vishing
Phishing conducted through a voice channel.
10
New cards
SMiShing
Phishing conducted through SMS or text messaging.
11
New cards
Pharming
Redirecting a victim to a malicious location through DNS spoofing.
12
New cards
Typosquatting
Using a cousin domain that closely resembles a trusted domain.
13
New cards
Email spoofing
Making an email appear to come from a trusted sender, including through From-field confusion.
14
New cards
Business email compromise
Targeted phishing, vishing, or SMiShing against a specific person while posing as a colleague, business partner, or vendor.
15
New cards
What targeted attacks are associated with business email compromise?
Spear phishing, whaling, CEO fraud, and angler phishing.
16
New cards
Brand impersonation
Creating fake phishing messages, business correspondence, or pharming sites that appear to represent a trusted brand.
17
New cards
Watering hole attack
Compromising a third-party site that the attacker knows is regularly used by the target.
18
New cards
Why may passive social-engineering techniques appeal to attackers?
They generally present less risk of detectio