Skip to content
ScopefileGet the app

Technique fileSocial engineering

Phishing, vishing, smishing and the rest: naming the social engineering attack

Each social engineering term names a channel and a target: email for phishing, a voice call for vishing, a text message for smishing, one hand-picked victim for spear phishing, an executive for whaling. The in-person techniques (tailgating, pretexting, baiting) work on doors and habits instead of inboxes. All of them sit in Module 9, Social Engineering.

Exam
312-50
Domain
4 · Network & perimeter
Targets
9

The terms, one line each

Phishing
Deceptive email sent in bulk to collect credentials or get a link clicked.
Spear phishing
Phishing written for a named person or a small group.
Whaling
Spear phishing whose target is a senior executive, such as a CEO or CFO.
Vishing
Voice phishing over a phone or VoIP call, increasingly with a cloned voice.
Smishing
SMS phishing: the lure is a text message, often with a short link.
Pharming
Users type the right address and still land on a fake site, because DNS records or a hosts file were tampered with. No lure message is needed.
Watering hole
A site the target group already visits is compromised and left waiting for them.
Pretexting
An invented identity and story (auditor, new hire, courier) that makes a request sound routine.
Baiting
A tempting freebie, such as a free download or a prize, whose real payload is malware or a credential prompt.
Quid pro quo
Something for something: the attacker trades a favor for what they want.
Tailgating
Slipping through a controlled door behind someone who does not notice.
Piggybacking
The same physical entry, but the authorized person knowingly holds the door.
Shoulder surfing
Reading a screen, keypad or document by watching nearby.
Dumpster diving
Recovering useful information from discarded paper, drives or devices.
Reverse social engineering
The attacker manufactures a problem, advertises themselves as the fix, and lets the victim make first contact.
Deepfake impersonation
AI-generated voice or video of a real person, named in the v13 course outline under impersonation.

Channel against targeting

Find the row from the channel, then the column from how the victim was chosen
Find the row from the channel, then the column from how the victim was chosenBroad audienceChosen targetEmailPhishingSpear phishing, whalingPhone callVishingVishing with a pretextText messageSmishingTargeted smishingWeb or DNSPharmingWatering holeIn personBaitingTailgating, pretexting

Put a name on the con

Short cases, one con each. Decide the channel and the audience first, and the term follows from the matrix above.

Answered 0/9Hits 0

T-01

What is the term for attempting to trick users into providing their account credentials through emails?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASpamming is sending bulk unsolicited messages, which need not try to steal credentials.
  2. BSpoofing means forging a sender's identity, which phishing often uses but which is not the attack itself.
  3. CCorrect: phishing uses deceptive emails, often with links to fake login pages, to trick users into handing over credentials.
  4. DSmishing is phishing delivered through SMS text messages rather than email.
T-02

A SOC analyst is reviewing multiple suspicious email reports. Which characteristic MOST definitively distinguishes a message as a targeted spear-phishing attack rather than a generic mass-phishing campaign?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AUrgent password reset demands appear in mass phishing too, so urgency does not show the message was tailored to the recipient.
  2. BGeneric invoice lures with macro documents are common in broad campaigns, so this does not indicate individual targeting.
  3. CCorrect: accurate internal project names and the recipient's real manager show prior research on that person, which defines spear phishing.
  4. DLook-alike domains are used in both mass and targeted campaigns, so they alone do not prove the attack was tailored.
T-03

Companies often train their employees to recognize and report phone calls from individuals pretending to be IT support, attempting to gather sensitive information. What type of social engineering attack does this describe?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABaiting lures victims with something tempting, such as an infected USB drive, rather than an impersonation phone call.
  2. BCorrect: vishing, or voice phishing, uses phone calls with pretexts such as fake IT support to extract sensitive information.
  3. CTailgating is physically following an authorized person through a secured entrance.
  4. DPhishing broadly means fraudulent messages, usually email, while the phone-based variant has its own name.
T-04

What term is used when an attacker uses text messaging to deceive a target into revealing confidential information?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APharming redirects users to fraudulent sites by tampering with DNS or host files rather than sending deceptive texts.
  2. BShoulder surfing means watching someone enter information, such as a PIN or password, in person.
  3. CPhishing is the email-based form, while text messaging attacks have a more specific name.
  4. DCorrect: smishing is phishing over SMS or messaging apps, often with urgent links about deliveries or account problems.
T-05

What is tailgating in the context of cybersecurity?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: tailgating is slipping through a secured door behind an authorized person, which mantraps and badge-per-person policies prevent.
  2. BSending deceptive emails to harvest credentials is phishing, not a physical intrusion.
  3. CSearching discarded trash for sensitive documents is dumpster diving.
  4. DListening in on conversations to collect information is eavesdropping.
T-06

In a corporate environment, employees are advised not to plug in unknown USB drives found in or around the office. What type of social engineering attack does this help prevent?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. APretexting builds an invented scenario to persuade someone to share information, rather than leaving infected media to be found.
  2. BQuid pro quo offers a service or favor in exchange for information or access.
  3. CCorrect: baiting leaves tempting media like USB drives where victims will find and plug them in, and blocking unknown removable media counters it.
  4. DPhishing delivers deceptive messages electronically rather than relying on physical media left lying around.
T-07

Which social engineering technique involves an attacker offering a service or benefit in exchange for information or access?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATailgating is following an authorized person through a secured door, not offering anything in exchange.
  2. BPretexting relies on a fabricated scenario or identity to justify a request, not on a trade of benefits.
  3. CBaiting dangles something tempting, like a free download or USB drive, but offers no service in return for information.
  4. DCorrect: quid pro quo trades a benefit, such as fake tech support or a gift, for credentials or access.
T-08

Implementing privacy filters on all computer monitors in an organization helps prevent which type of social engineering attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABaiting relies on tempting media or downloads, which screen filters do nothing to stop.
  2. BTailgating is a physical entry attack countered by mantraps and access control, not monitor filters.
  3. CCorrect: privacy filters narrow a screen's viewing angle so people nearby cannot read passwords or data over someone's shoulder.
  4. DPhishing arrives through messages and is countered by filtering and training, not by screen filters.
T-09

While working undercover, you set up a scenario where a target approaches you for technical help. You exploit this opportunity by posing as a legitimate tech support representative and gather confidential information from them. What type of social engineering attack is this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABaiting leaves a lure for the victim to take, rather than waiting for a request for help.
  2. BPhishing uses deceptive messages sent to the victim, whereas here the victim initiates contact.
  3. CPretexting also uses an invented role, but the attacker initiates contact, while here the target reaches out first.
  4. DCorrect: in reverse social engineering the attacker arranges for the victim to seek help, then poses as the trusted helper to obtain information.

High yield, low yield

Module 9 is one of five modules in Domain 4, Network and Perimeter Hacking, which blueprint v5.0 weights at 24% of the exam (checked Oct 11, 2026). The social engineering slice is mostly vocabulary: cheap to learn, expensive to miss.

Learn well

  • The phishing family by channel and audience (the matrix above).
  • Tailgating against piggybacking: consent is the only difference.
  • Insider threat types: negligent, malicious, and a compromised account all count as insiders.
  • Which defense answers which technique, listed below.

Skim

  • Names of phishing kits and campaign tools.
  • Long lists of persuasion principles. Authority, urgency and scarcity drive most pretexts; that is enough.

Defenses by technique

Awareness training and an easy reporting path cover email, voice and text lures. Phishing-resistant MFA limits what a stolen password is worth. Mantraps, turnstiles and one-badge-one-person rules stop unauthorized entry behind staff. A clean-desk policy and cross-cut shredding defeat dumpster diving. Pharming is a DNS problem, so DNSSEC and locked-down resolvers do more than training. Text-message lures overlap with the mobile platforms module, where one-time-code theft reappears.

Edge cases worth a minute

Is pharming a kind of phishing?

It belongs to the same family because the goal is the same: a fake site that collects credentials. The mechanism differs. Phishing needs the victim to act on a message; pharming redirects someone who typed the correct address.

When does spear phishing become whaling?

When the chosen target is a senior executive. The method is identical, so the victim's role is the only marker.

Does impersonation on social networks count as social engineering?

Yes. Blueprint v5.0 lists impersonation on social networking sites and identity theft inside Module 9, next to the classic techniques.

Sources