🌍 Ethical Hacking · subject

Ethical Hacking Social Engineering Syllabus

Every chapter and topic of Social Engineering examined in Ethical Hacking — 3 chapters, 10 topics, plus 50 flashcards written against it.

3Chapters
10Topics
0Sub-topics
~8hEst. first pass
6%Of Ethical Hacking
50Flashcards

Social Engineering syllabus — full chapter and topic list

Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Social Engineering in Ethical Hacking, not a summary of it.

  1. Social Engineering Concepts

    3 topics
    • What is Social Engineering?
    • Psychological Principles
    • Common Attack Vectors
  2. Types of Social Engineering Attacks

    4 topics
    • Phishing
    • Pretexting
    • Baiting
    • Tailgating
  3. Countermeasures

    3 topics
    • Security Awareness Training
    • Email Filtering
    • Incident Response Planning

Social Engineering flashcards for Ethical Hacking

18 of 50 cards from the Social Engineering deck — real questions with worked answers.

  1. What is social engineering in the context of cybersecurity?

    The psychological manipulation of people into performing actions or divulging confidential information. It exploits human trust and behavior rather than technical vulnerabilities, targeting the 'human element' as the weakest link in security.

  2. Why is social engineering often more effective than technical hacking?

    Because it targets human psychology (trust, fear, curiosity, helpfulness) which cannot be patched like software. Humans are considered the weakest link in the security chain, and manipulation bypasses technical controls like firewalls and encryption.

  3. What are the typical phases of a social engineering attack lifecycle?

    1) Information gathering / research (OSINT), 2) Developing rapport / establishing trust (hook), 3) Exploitation (play — extracting information or access), 4) Exit (closing interaction without arousing suspicion, covering tracks).

  4. Define the security term 'human-based' vs 'computer-based' social engineering.

    Human-based social engineering uses person-to-person interaction (impersonation, tailgating, shoulder surfing). Computer-based social engineering uses software/technology (phishing emails, pop-ups, fake websites, malware) to deceive victims.

  5. What is OSINT and its role in social engineering?

    OSINT (Open-Source Intelligence) is the collection of publicly available information (social media, company websites, public records) used during the reconnaissance phase to research targets and craft convincing, personalized attacks.

  6. List Robert Cialdini's six principles of persuasion exploited in social engineering.

    1) Reciprocity, 2) Commitment and Consistency, 3) Social Proof (Consensus), 4) Authority, 5) Liking, 6) Scarcity.

  7. How does the psychological principle of 'authority' aid a social engineer?

    People tend to obey figures of authority. Attackers impersonate executives, IT staff, or law enforcement so victims comply with requests without questioning them (e.g., a fake 'CEO' demanding an urgent wire transfer).

  8. How does the principle of 'scarcity/urgency' manipulate victims?

    Creating a sense of limited time or limited availability pressures victims into acting quickly without critical thinking (e.g., 'Your account will be locked in 24 hours — verify now'), reducing rational scrutiny.

  9. Explain the 'reciprocity' principle in social engineering.

    When someone does a favor for us, we feel obligated to return it. An attacker offers small help or a gift (free software, a favor) so the target feels compelled to reciprocate by granting a request or information.

  10. What is 'social proof' (consensus) as a manipulation tactic?

    People look to others' behavior to decide their own. An attacker claims 'all your colleagues have already updated their credentials here' to make the request seem normal and expected, lowering the victim's guard.

  11. How does the 'liking' principle contribute to a successful attack?

    People are more easily persuaded by those they like or find similar to themselves. Attackers build rapport, use flattery, shared interests, or a friendly demeanor to lower the target's defenses.

  12. What common emotions do social engineers exploit to bypass rational thinking?

    Fear, greed, curiosity, urgency, trust, helpfulness (desire to be helpful), and empathy. Triggering strong emotions pushes victims to act on impulse rather than following security procedures.

  13. Name at least five common social engineering attack vectors.

    Phishing (email), vishing (voice/phone), smishing (SMS), pretexting, baiting, tailgating/piggybacking, quid pro quo, shoulder surfing, dumpster diving, and watering hole attacks.

  14. What is a 'watering hole' attack?

    An attacker compromises a legitimate website frequently visited by the target group, infecting it with malware so that visitors are compromised when they browse the trusted site.

  15. Define 'dumpster diving' as a reconnaissance technique.

    Searching through an organization's trash (physical or digital) to recover discarded sensitive information such as documents, passwords, org charts, or hardware that aids an attack.

  16. What is 'shoulder surfing'?

    Directly observing a person (over their shoulder or via cameras/binoculars) to steal information such as PINs, passwords, or confidential data as it is typed or displayed.

  17. Define 'quid pro quo' social engineering with an example.

    An attack offering a service or benefit in exchange for information or access. Example: an attacker posing as IT support offers to 'fix' a problem in exchange for the user's login credentials.

  18. What is phishing?

    A social engineering attack, typically via email, that impersonates a trustworthy entity to trick victims into revealing sensitive data (credentials, financial info) or into clicking malicious links/attachments that install malware.

See more Social Engineering flashcards →

Planning Social Engineering for Ethical Hacking

Social Engineering is about 6% of the Ethical Hacking syllabus by topic count — 10 of 173 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 8 hours.

The heaviest chapters are Types of Social Engineering Attacks (4 topics), Social Engineering Concepts (3 topics), Countermeasures (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.

Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.

Social Engineering (Ethical Hacking) FAQ

What is in the Ethical Hacking Social Engineering syllabus?

Social Engineering is split into 3 chapters — Social Engineering Concepts, Types of Social Engineering Attacks and Countermeasures, containing 10 topics and 0 sub-topics in total.

How is Social Engineering structured in the Ethical Hacking syllabus?

3 chapters. Social Engineering accounts for about 6% of the topics in the whole Ethical Hacking syllabus (10 of 173).

How long should I spend on Social Engineering for Ethical Hacking?

Budget around 8 hours for a first pass through Social Engineering — about 45 minutes per topic plus 12 minutes per sub-topic across its 10 topics. Add revision cycles on top.

Are there flashcards for Ethical Hacking Social Engineering?

Yes — a 50-card Social Engineering deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.