โ† All Certified Ethical Hacker Flashcard Decks

Social Engineering and Physical Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Social Engineering and Physical Security flashcards as text
  1. An attacker sends an email claiming to be from the IT helpdesk, urgently requesting the user reset their password via an included link. Which social engineering principle is MOST being exploited?

    Answer: Authority and urgency

    Impersonating IT (authority) plus an urgent deadline pressures the victim into acting without verifying.

  2. What is the term for digging through an organization's trash to recover sensitive documents, sticky notes, or discarded media?

    Answer: Dumpster diving

    Dumpster diving recovers improperly discarded information that may contain credentials or internal data.

  3. An attacker drops several USB flash drives labeled 'Salaries 2026' in a company parking lot hoping employees plug them in. This attack is called:

    Answer: Baiting

    Baiting lures victims with an enticing physical or digital item that delivers malware when used.

  4. Which countermeasure is MOST effective against tailgating into a secure facility?

    Answer: Mantraps with anti-passback controls

    A mantrap allows only one authenticated person through at a time, preventing an unauthorized follower.

  5. A phishing attack specifically targeting a company's CEO or other high-value executives is known as:

    Answer: Whaling

    Whaling is spear phishing aimed at senior executives or 'big fish' for high-impact access.

  6. During a pretexting call, an attacker pretends to be a vendor needing to 'verify' an account before processing a refund. What is the attacker primarily relying on?

    Answer: A fabricated scenario to build trust

    Pretexting uses an invented but believable backstory to manipulate the target into disclosing information.

  7. Which security awareness practice BEST reduces the success rate of social engineering attacks over time?

    Answer: Regular phishing simulations and training

    Ongoing simulated phishing and training condition employees to recognize and report manipulation attempts.