L5. Social Engineering: Phishing, Vishing & Pretexting
Course outlineLesson 5 of 20
Social engineering attacks target human psychology rather than technical vulnerabilities. The Security+ exam tests your ability to identify attack techniques and select appropriate defenses.
Why Social Engineering Works
Social engineering exploits human tendencies: trust, authority, urgency, fear, and helpfulness. No amount of technical security controls fully prevents it, which is why user awareness training is a required control in every major security framework.
Phishing Variants
Phishing: mass-delivered fraudulent email impersonating a trusted brand (bank, vendor, IT helpdesk) to steal credentials or deliver malware. Spear phishing: targeted phishing using personalized details about the victim (name, role, recent project) to increase believability. Whaling: spear phishing targeting executives (CEO, CFO) who have high-value access and authority to authorize wire transfers. Vishing: voice phishing via phone call. Attacker impersonates IT support, bank, or government agency. Smishing: phishing via SMS text message. Often includes a malicious link. Business Email Compromise (BEC): attacker impersonates a trusted person (CEO, vendor) via email to trick employees into transferring funds or sharing sensitive data.Other Social Engineering Techniques
Pretexting: fabricating a scenario to manipulate the target (e.g., posing as an auditor who needs system access). Baiting: leaving malware-loaded USB drives in parking lots or lobbies; relies on victim curiosity. Quid pro quo: offering a service (e.g., fake IT support) in exchange for credentials or access. Tailgating/Piggybacking: physically following an authorized person through a secured door without using credentials.Defenses
- Security awareness training and phishing simulations
- Email authentication: SPF, DKIM, and DMARC reduce spoofed email delivery
- MFA: even if credentials are stolen, MFA limits the damage
- Caller ID verification procedures for sensitive requests
- Mantrap/airlock entry systems to prevent tailgating
- ✓Spear phishing is targeted using victim-specific details; whaling specifically targets executives
- ✓Vishing uses voice calls; smishing uses SMS; BEC impersonates a trusted person to authorize fraudulent transactions
- ✓Pretexting involves creating a fabricated scenario (false identity/situation) to manipulate the target
- ✓DMARC + SPF + DKIM together authenticate email senders and reduce spoofed email delivery
- ✓MFA limits the impact of credential theft from phishing; even stolen passwords alone are insufficient to access MFA-protected accounts
1. An attacker calls an employee, claims to be from the IT helpdesk, and asks for their password to fix an urgent account issue. Which technique is this?
2. An attacker leaves several USB drives labeled "Q4 Salary Data" in the company parking lot. Which social engineering technique is this?
3. Which combination of email authentication standards is most effective at preventing domain spoofing in phishing attacks?
Recommended: Pluralsight
Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.