Social Engineering Flashcards
1
Q
The social engineer (attacker) focuses on 4 things …
A
- Goal
- Receiver
- Message
- Channel
2
Q
Name 4 ways to mitigate social engineering
A
Any four from:
- Education
- Increase awareness of information being released
- Identify valuable assets
- Policy & Awareness
- Keep software up to date
- Make all employees equal partners
- Implement need-to know information dissemination
- Be suspicious
- Not punishing when employees do not give out information.
3
Q
Name 3 Common types of Social Engineering attacks:
A
- Phishing
- In-Person
- Baiting - Leaving USBs lying around
- Piggybacking
- Physical Security
4
Q
Goal - What does the social engineer want to achieve?
Give 2.
A
Getting information
Gaining Access
Malware
Getting someone to perform an action
5
Q
How may an attacker Build Rapport?
Give 2.
A
- Draw the person out (can be done simply by talking to the person)
Building Rapport
- People tend to be polite
- People like to appear intelligent
- If you are praised you talk more
- Most people only lie when they have a motivation to lie
- People respond when others appear to care about them