🌍 Ethical Hacking · flashcards

Ethical Hacking Social Engineering Flashcards

50 question-and-answer cards covering Social Engineering as it is examined in Ethical Hacking. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

50Cards in deck
24Free preview
10Syllabus topics
~212Chars per answer
FreePrice

24 sample cards from the Social Engineering deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is 'impersonation' in social engineering?

    Assuming a false identity — such as an employee, contractor, IT support, delivery person, or authority figure — to gain trust and access to information, systems, or restricted physical areas.

  2. What is baiting?

    An attack that lures victims with something enticing (physical or digital) to trigger a compromise — e.g., leaving malware-infected USB drives labeled 'Payroll' in a parking lot, or offering free movie/software downloads that carry malware.

  3. How does baiting differ from quid pro quo?

    Baiting relies on the victim's greed/curiosity by dangling an attractive item they take on their own initiative. Quid pro quo offers a service/benefit in direct exchange for information or an action requested by the attacker.

  4. Why are USB drops (a form of baiting) effective?

    They exploit human curiosity and helpfulness. Studies show a large percentage of found USB drives are plugged in by finders, executing malware or auto-run payloads that give attackers a foothold inside the network.

  5. What is tailgating (piggybacking)?

    A physical social engineering attack where an unauthorized person follows an authorized individual through a secured entrance — e.g., slipping through a door someone else badged open, often while posing as a delivery worker or carrying items.

  6. What is the subtle difference between tailgating and piggybacking?

    In tailgating the authorized person is unaware they are being followed. In piggybacking the authorized person knowingly grants access (e.g., holds the door out of courtesy). Both bypass physical access controls.

  7. What physical security controls help prevent tailgating?

    Mantraps/access-control vestibules, turnstiles, badge readers with anti-passback, security guards, visitor escort policies, CCTV, and employee awareness to challenge unbadged strangers ('challenge culture').

  8. What is a mantrap (access-control vestibule)?

    A small space with two interlocking doors where the second door cannot open until the first is closed and the person is authenticated, allowing only one person through at a time to prevent tailgating.

  9. What is the primary purpose of Security Awareness Training?

    To educate employees to recognize, resist, and report social engineering attacks — transforming the human weakest link into a 'human firewall' and building a security-conscious organizational culture.

  10. What are effective components of a security awareness program?

    Regular training sessions, simulated phishing campaigns, clear reporting procedures, policy education, role-based training, gamification, ongoing reinforcement, and metrics to measure improvement over time.

  11. What is a simulated phishing campaign and why is it used?

    A controlled, fake phishing exercise sent to employees to measure susceptibility and provide teachable moments. It identifies at-risk users, reinforces training, and tracks the click/report rate over time.

  12. Define the phishing 'click rate' and 'report rate' metrics.

    Click rate = percentage of recipients who clicked the simulated phishing link (lower is better). Report rate = percentage who correctly reported the email to security (higher is better). Both gauge awareness program effectiveness.

  13. How is the phishing simulation click rate calculated?

    $$\text{Click Rate} = \frac{\text{Number of users who clicked}}{\text{Total number of recipients}} \times 100\%$$

  14. What is email filtering and what does it protect against?

    The automated screening of inbound/outbound email to block spam, phishing, malware, and spoofed messages before they reach users' inboxes — a key technical defense layer against email-based social engineering.

  15. What are SPF, DKIM, and DMARC?

    Email authentication protocols. SPF (Sender Policy Framework) verifies sending IPs are authorized for a domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature verifying integrity/origin. DMARC ties SPF/DKIM together with a policy for handling failures and reporting.

  16. What does the DMARC 'p=' policy tag control, and what are its values?

    It tells receivers how to handle messages that fail authentication. Values: p=none (monitor only), p=quarantine (mark as spam/junk), and p=reject (block the message outright).

  17. Name common techniques used by email filters to detect phishing.

    Sender authentication (SPF/DKIM/DMARC), reputation/blocklists (RBLs), keyword and heuristic analysis, URL/link scanning and sandboxing, attachment scanning, machine-learning content classifiers, and anti-spoofing/display-name checks.

  18. What is email sandboxing (detonation)?

    A technique where suspicious attachments or links are opened/executed in an isolated virtual environment to observe behavior for malicious activity before delivering the message to the user.

  19. What is the purpose of an Incident Response (IR) plan for social engineering?

    To provide a predefined, structured procedure for detecting, containing, eradicating, and recovering from a successful social engineering attack, minimizing damage and enabling learning to prevent recurrence.

  20. List the phases of the NIST/SANS incident response lifecycle.

    1) Preparation, 2) Detection and Analysis (Identification), 3) Containment, 4) Eradication, 5) Recovery, 6) Post-Incident Activity (Lessons Learned). SANS lists six; NIST groups some into four phases.

  21. What immediate steps should a user take after falling for a phishing attack?

    Report it to security/IT immediately, disconnect the affected device from the network, change compromised credentials, preserve evidence (don't delete the email), and monitor accounts for suspicious activity.

  22. What is the difference between containment and eradication in IR?

    Containment limits the spread/damage of an incident (isolating systems, disabling accounts) to stop it worsening. Eradication removes the root cause and artifacts (malware, backdoors, attacker access) from the environment entirely.

  23. Why is the 'Lessons Learned' (post-incident) phase important?

    It reviews what happened, how it was handled, and how defenses can improve. Findings feed back into policies, awareness training, and controls to reduce the likelihood and impact of future social engineering incidents.

  24. What is 'reverse social engineering'?

    An attack where the attacker manipulates the victim into initiating contact and asking for help. Typically involves three steps: sabotage (create a problem), advertising (pose as the fixer), and assisting (extract info while 'helping').

What this deck covers

The Social Engineering deck follows the Ethical Hacking Social Engineering syllabus — 3 chapters and 10 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 16.7 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 212 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Social Engineering flashcards FAQ

How many Social Engineering flashcards are in this Ethical Hacking deck?

50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Ethical Hacking flashcards free?

Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.

What do the Social Engineering cards cover?

They follow the Ethical Hacking Social Engineering syllabus — 3 chapters and 10 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.