Social Engineering Flashcards

(18 cards)

1
Q

What are the 2 possible goals in Social Engineering?

A

Psychologically manipulate people into doing something/releasing info, Gather info left by people

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What 2 reasons allow Social Engineering to work?

A

People are vulnerable to manipulation, People can’t easily be patched

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 6 stages in an SE attack? 1)🥊2) 🛜 3) 📖 4) 💏5) 😈6) 💼

A

1) Attack Formulation 2) Information Gathering 3) Preparation 4) Develop Relationship 5) Exploit Relationship 6) Debrief (maintain and ease out of relationship as to not cause suspicion)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 2 types of Commication in Social Engineering attacks?

A

Direct Communication (attacker to victim), Indirect Communication (attacker uses third party website to talk to victims)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is meant by Bidirectional communication?

A

Direct Communication between attacker and victim, both speak

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is meant by Unidirectional communication?

A

Direct Communication between attacker and victim, attacker doesn’t expect victim reply. e.g. email directly to victim, but victim wouldn’t respond to email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the 6 Compliance Principles?

A

Friendship or Liking, Commitment or Consistency, Scarcity. Reciprocity, Social Validation, Authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Pretexting?

A

Creating a fake scenario to convince you (e.g. “You booked this flight, call us for a refund”)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is meant by Compliance Principles “Commitment or Consistency”?

A

Ask little bit of info from victim, over time will divulge more as they are committed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is meant by Compliance Principles “Scarcity”?

A

Scarcity in resources or time, make them feel rushed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is meant by Compliance Principles “Social Validation”?

A

This brand new app everyone has, don’t miss out! Download

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the 6 entities in an SE attack? (the circle diagram)

A

1) Social Engineer (attacker) 2) Target 3) Goal 4) Medium 5) Technique 6) Compliance Principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are 4 Social Engineering techniques?

A

1) Info Gathering, Interaction with Target, Tailgating, Baiting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are 3 ways of Info Gathering technique?

A

Dumpster Dive, Shoulder Surf, Search Internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are 3 ways of Interaction with Target technique?

A

Phishing, Spear Phishing, Visihing, Physical Impersonation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Spear Phishing?

A

Phishing specifically tailored to a particular victim

17
Q

What is Baiting?

A

Bait with curiosity, e.g. infected USB

18
Q

What is Tailgating?

A

Walk into building behind someone