TechKnowSurge
CompTIA Security+ 2.2 CompTIA Network+ 4.2 CompTIA Security+ 5.6
InteractiveSecurityFree

Social Engineering Technique Identifier

Sort social engineering scenarios into the correct technique: Phishing, Vishing, Smishing, Pretexting, Baiting, Tailgating, Quid Pro Quo, or Spear Phishing.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Eight bins looks like eight things to memorize. It is really one attack — social engineering, working on a person instead of a machine — sorted by two questions: what channel did it arrive on, and what was the lure? The channel question settles the first three. Phishing, vishing and smishing are the same trick down three different pipes: email, voice call, SMS. The words do not decide which one it is — the pipe does. "You won a prize, click to claim" is smishing when it arrives as a text and phishing when it arrives as an email, and reading the message alone will never tell you. Pretexting is the one that breaks the pattern, and it is where most wrong answers land. It is defined by the fabricated identity, not by the channel, so it can ride any of them. The call to HR from a "payroll auditor" is a phone call and still is not vishing: the invented role is what buys the salary data. Same for the fire inspector at the server room — a story got them through the door, so it is pretexting, not tailgating. Tailgating uses no story at all, just proximity and a door someone politely holds. Baiting and quid pro quo blur because both offer the victim something. Bait is an object, left where someone will find it and pick it up: the parking-lot USB, the free download. Quid pro quo is a transaction with a person — a service offered in exchange for something, and the something is almost always credentials. Spear phishing, finally, is phishing plus homework. Generic phishing is a blast that could be addressed to anyone; spear phishing names your CFO, their boss, and a vendor you actually use. The tell is specificity, not tone — a well-written email is not automatically targeted, and a targeted one is dangerous precisely because everything in it checks out.

What you'll learn

Aligned to

CompTIA Security+
2.2 Explain common threat vectors and attack surfaces.
5.6 Given a scenario, implement security awareness practices.
CompTIA Network+
4.2 Summarize various types of attacks and their impact to the network.

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Smishing
A social engineering attack delivered via SMS text messages that tricks recipients into clicking malicious links, calling fraudulent numbers, or revealing sensitive information such as account credentials or financial data.
Pretexting
A social engineering technique in which an attacker fabricates a convincing scenario — such as impersonating IT support, a vendor, or an authority figure — to manipulate a target into performing an action or disclosing sensitive information.
Baiting
A social engineering technique that uses an enticing offer or lure to trick a victim into taking an action that compromises their security.
Tailgating
A physical security breach where an unauthorized person follows an authorized individual through a secured entry point without presenting credentials.
Quid Pro Quo
A social engineering attack technique involving an overt exchange of something for something, such as offering a benefit in return for access, credentials, or sensitive information.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Whaling
A type of spear phishing attack that targets high-level executives or senior leadership within an organization, such as CEOs or C-suite members.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →