โ† All Certified Ethical Hacker Flashcard Decks

Social Engineering and Physical Security Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Social Engineering and Physical Security flashcards as text
  1. An attacker calls an employee pretending to be tech support and asks them to read out a one-time code just texted to them. This voice-based attack is called:

    Answer: Vishing

    Vishing (voice phishing) uses phone calls to socially engineer victims into revealing sensitive data.

  2. What is 'shoulder surfing' in the context of physical security?

    Answer: Observing a victim's screen or keypad to steal information

    Shoulder surfing is directly watching someone enter credentials, PINs, or view confidential data.

  3. A fraudulent SMS message claiming a package delivery failed and asking the user to click a link is an example of:

    Answer: Smishing

    Smishing is phishing conducted through SMS text messages.

  4. Which physical control prevents an attacker from cloning a proximity badge by capturing its RFID signal from a distance?

    Answer: Shielded badge holders (RFID-blocking sleeves)

    RFID-blocking sleeves prevent unauthorized reading or cloning of proximity card signals.

  5. In a 'quid pro quo' social engineering attack, the attacker primarily offers:

    Answer: A benefit or service in exchange for information or access

    Quid pro quo trades something of value (e.g., 'free IT help') for the victim's cooperation.

  6. An attacker compromises a website frequently visited by employees of a target company to infect them. This technique is known as a:

    Answer: Watering hole attack

    A watering hole attack poisons a trusted, commonly visited site to compromise its specific visitors.

  7. Which is the BEST first response if an employee suspects they fell for a phishing email and entered their credentials?

    Answer: Immediately report it and change the affected password

    Prompt reporting and password changes limit the window an attacker can use the stolen credentials.