Social Engineering
Computer Science Master
Question 1. What is the primary goal of social engineering attacks?
□ A. To physically damage computer hardware □ B. To exploit human psychology to gain unauthorized access □ C. To improve network performance □ D. To develop new encryption algorithms
Question 2. Which social engineering attack involves sending deceptive emails or messages to trick individuals into revealing sensitive information?
□ A. Baiting □ B. Pretexting □ C. Phishing □ D. Vishing
Question 3. How does spear phishing differ from general phishing?
□ A. It targets a broad group rather than individuals □ B. It uses phone calls exclusively □ C. It customizes messages to specific individuals or organizations □ D. It involves offering free downloads
Question 4. Which of the following is an effective defense against social engineering attacks?
□ A. Leaving access controls open to all employees □ B. Enabling Multi-Factor Authentication (MFA) □ C. Ignoring suspicious emails □ D. Disabling incident response plans
Question 5. What is baiting in the context of social engineering?
□ A. Creating fake scenarios to obtain information □ B. Offering something appealing to lure victims into a trap □ C. Sending targeted emails to executives □ D. Making phone calls to verify identity
Question 6. Fill in the blank(s)
Social engineering attacks often exploit ________________________ to gain unauthorized access.
Question 7. Fill in the blank(s)
In __________, attackers use phone calls to trick individuals into revealing sensitive information.
Question 8. Fill in the blank(s)
Enabling ________________________________________ adds an extra layer of security against social engineering.
Question 9. Fill in the blank(s)
_______________ involves fabricating a scenario to manipulate someone into giving away information.
Question 10. Fill in the blank(s)
Advanced ______________________ can reduce phishing attempts by detecting suspicious messages.
Question 11. What is spear phishing and how does it increase the chance of success?
Question 12. Name two defenses organizations can implement to protect against social engineering attacks.
Question 13. What role does incident response planning play in defending against social engineering attacks?
Question 14. Why is verification important when responding to requests for sensitive information?
Question 15. Explain how psychological manipulation is used in social engineering attacks and why it is effective.
Question 16. Describe the differences between phishing, spear phishing, and vishing, including how each operates.
Question 17. Discuss multiple strategies an organization can adopt to defend against social engineering attacks and explain how they contribute to security.