Social Engineering and Identity Theft Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/24

flashcard set

Earn XP

Description and Tags

This set covers definitions, techniques, and countermeasures related to Social Engineering and Identity Theft based on the ITE490 lecture notes.

Last updated 11:18 AM on 6/11/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

25 Terms

1
New cards

Social Engineering (SE)

The art of convincing people to reveal confidential information, often depending on the fact that people are unaware of their valuable information and are careless about protecting it.

2
New cards

Human-based Social Engineering

A type of social engineering that gathers sensitive information through person-to-person interaction.

3
New cards

Computer-based Social Engineering

Social engineering carried out with the help of computer software that attempts to retrieve desired information.

4
New cards

Mobile-based Social Engineering

Social engineering carried out with the help of mobile applications, such as publishing malicious apps with attractive features.

5
New cards

Impersonation

A common human-based technique where an attacker pretends to be a legitimate or authorized person to trick a target into revealing sensitive information.

6
New cards

Eavesdropping

The unauthorized listening of conversations or reading of messages by intercepting audio, video, or written communication.

7
New cards

Shoulder Surfing

Direct observation techniques, such as looking over someone's shoulder or using binoculars, to obtain information like passwords, PINs, or card numbers.

8
New cards

Dumpster Diving

The act of looking for treasure or valuable sensitive information in someone else's trash.

9
New cards

Reverse Social Engineering

A situation where an attacker presents themselves as an authority (e.g., tech support) so that the target seeks their advice and offers information voluntarily.

10
New cards

Piggybacking

When an authorized person intentionally or unintentionally allows an unauthorized person to pass through a secure door, such as when someone claims to have forgotten their ID badge.

11
New cards

Tailgating

When an unauthorized person wearing a fake ID badge enters a secured area by closely following an authorized person through a door requiring key access.

12
New cards

Pop-up Windows

Windows that suddenly appear while surfing the Internet asking for user login or sign-in information.

13
New cards

Hoax Letters

Emails that issue warnings to the user about new viruses, Trojans, or worms that may harm their system.

14
New cards

Chain Letters

Emails that offer free gifts like money or software on the condition that the user forwards the mail to others.

15
New cards

Spam Email

Irrelevant, unwanted/unsolicited email used to collect financial information, social security numbers, and network information.

16
New cards

Phishing

An illegitimate email falsely claiming to be from a legitimate site that attempts to acquire user personal or account information by redirecting them to fake webpages.

17
New cards

Spear Phishing

A targeted phishing attack directed at specific individuals or a small group in an organization, typically generating a higher response rate than normal phishing.

18
New cards

Insider Attack

A threat from within an organization, such as a disgruntled employee seeking revenge or a competitor's plant spying to steal critical secrets.

19
New cards

Identity Theft

A crime in which an imposter obtains personally identifiable information, such as name, credit card number, or social security number, for fraudulent purposes.

20
New cards

Social-Engineer Toolkit (SET)

An open-source Python-driven tool aimed at penetration testing around social engineering.

21
New cards

Separation and Rotation of Duties

A prevention strategy for insider threats involving the distribution of tasks among different employees to ensure no single person has total control.

22
New cards

Least Privilege

A security principle where users are granted only the minimum levels of access or permissions needed to perform their job functions.

23
New cards

Two-Factor Authentication

A countermeasure that uses a second factor instead of just fixed passwords for high-risk network services like VPNs.

24
New cards

PhishTank

A collaborative clearing house for data and information about phishing on the Internet which provides an open API for developers.

25
New cards

Netcraft

An anti-phishing toolbar used to report phishing sites and identify the risk rating and location of web space.