Social Engineering and Physical Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Social Engineering and Physical Security flashcards as text
An attacker calls an employee pretending to be tech support and asks them to read out a one-time code just texted to them. This voice-based attack is called:
Answer: Vishing
Vishing (voice phishing) uses phone calls to socially engineer victims into revealing sensitive data.
What is 'shoulder surfing' in the context of physical security?
Answer: Observing a victim's screen or keypad to steal information
Shoulder surfing is directly watching someone enter credentials, PINs, or view confidential data.
A fraudulent SMS message claiming a package delivery failed and asking the user to click a link is an example of:
Answer: Smishing
Smishing is phishing conducted through SMS text messages.
Which physical control prevents an attacker from cloning a proximity badge by capturing its RFID signal from a distance?
Answer: Shielded badge holders (RFID-blocking sleeves)
RFID-blocking sleeves prevent unauthorized reading or cloning of proximity card signals.
In a 'quid pro quo' social engineering attack, the attacker primarily offers:
Answer: A benefit or service in exchange for information or access
Quid pro quo trades something of value (e.g., 'free IT help') for the victim's cooperation.
An attacker compromises a website frequently visited by employees of a target company to infect them. This technique is known as a:
Answer: Watering hole attack
A watering hole attack poisons a trusted, commonly visited site to compromise its specific visitors.
Which is the BEST first response if an employee suspects they fell for a phishing email and entered their credentials?
Answer: Immediately report it and change the affected password
Prompt reporting and password changes limit the window an attacker can use the stolen credentials.