TechKnowSurge
CompTIA PenTest+ 4.8 CompTIA Security+ 2.2 CompTIA PenTest+ 3.3 CompTIA Security+ 5.6
InteractiveSecurityFree

Social Engineering Technique Identifier (Advanced)

Sort advanced social engineering scenarios into 8 technique bins: Pretexting, Vishing, Smishing, Baiting, Tailgating, Quid Pro Quo, Shoulder Surfing, and Whaling.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

The base version of this activity sorts by channel — email, phone, text, door. This one does not let you do that, because the eight bins here overlap on channel and separate on mechanism instead. The question to ask each scenario is not how did it arrive, it is what is the attacker actually relying on to make this work. Answer that and the bin follows. Start with the hardest pair, because it is the one that decides whether you have understood the rule. Two of these scenarios are phone calls in which the attacker claims to be someone they are not, and they land in different bins. An attacker posing as an IT auditor to get the helpdesk to reset a privileged account is Pretexting. A caller claiming to be Microsoft Support and asking for remote access is Vishing. Both involve a phone. Both involve a lie about identity. The difference is what carries the attack. In the auditor call, the fabricated role is the whole weapon: helpdesks are built to serve authorized staff, and an auditor is precisely the kind of person a helpdesk is trained not to obstruct. Strip the invented identity out and nothing remains — there is no attack. That is what pretexting names, and it is why the same fabricated-auditor script works over email, in person, or on the phone. In the Microsoft Support call, the invented identity is thin and generic; the attack runs on the live voice itself — the urgency, the pressure, the fact that a real human is talking you through granting access in real time, which a text or an email cannot do. Vishing names the channel because the channel is doing the work. So: if removing the phone kills the attack, it is vishing. If removing the invented role kills the attack, it is pretexting. The new-contractor scenario is pretexting for the same reason as the auditor — the plausible-newcomer role is what makes the credential request sound routine, and the request would work through any medium. Smishing gets no such argument, and that is deliberate: it is here as the fixed point. Both text-message items are unambiguous, so if you find yourself hesitating over them you have started overthinking the exercise rather than reading it. A link in an SMS claiming your bank account is locked, and an SMS about a failed parcel delivery, are the two most common smishing lures in the world. Baiting is where the second real distinction lives, and it is with quid pro quo. Both offer the victim something. Baiting leaves the offer lying there and waits — the USB drive labelled Q3 Payroll Data on a desk works on curiosity, and the pirated game bundling a RAT works on the desire for something free. The attacker never interacts with the victim at all. Quid pro quo is a transaction between two people, in real time, with an explicit trade: help for credentials. The printer-jam offer and the IT tech offering to fix a slow computer are both someone standing in front of a user proposing an exchange. Bait is left; a quid pro quo is negotiated. Note that the torrented game has no physical object in it, which catches people who have memorized baiting as the USB drive attack. The medium is irrelevant; the lure is the technique. Tailgating covers both physical-entry scenarios, and one of them deserves its finer name. The food-delivery uniform following an employee through a badge-controlled door is tailgating in the strict sense — the attacker exploits the door being open without the employee ever agreeing to anything. Someone holding the door for an attacker carrying a laptop bag is technically piggybacking, because the authorized person consented; they were deceived into a courtesy rather than bypassed. That term is in the vocabulary for this set, and it is worth knowing, but CompTIA's exam objectives fold both under tailgating, which is why both items sort there. The laptop bag matters for the same reason the uniform does: props manufacture the belonging that makes holding the door feel obviously correct. Shoulder surfing is the only technique here in which the attacker never communicates with the victim, and that is its whole identity. Reading an email login over someone's shoulder in a coffee shop and watching a PIN entered at an ATM from across the aisle involve no lie, no offer, no message and no door — just observation. This is what separates it from pretexting, which needs a story, and from tailgating, which needs the victim's movement through a controlled point. The ATM item is worth pausing on: from across the aisle is not shoulder-level proximity, and the technique is named for a posture it does not actually require. Distance is not the test. Direct observation of information as it is entered is the test, which is why the same category covers a telephoto lens and a camera on a ceiling. Whaling is the bin that most often gets missed, because it looks like spear phishing and is a subtype of it. Every whaling attack is a spear phishing attack; the reverse does not hold. The discriminator is only the seniority of the target. Both items here name their target explicitly — a CEO and a CTO — and that is not incidental scenario colour, it is the answer. The reason the distinction earns its own word is that the consequences differ in kind rather than degree. Executives can authorize wire transfers, waive controls, and instruct staff who will not question them, so a single success yields an outcome no ordinary compromised account can produce. The CEO item is a good illustration of the effort that justifies the term: travel plans, board member names and a spoofed CFO address all had to be researched first, which means reconnaissance preceded the email. The CTO item, referencing an acquisition to trigger a wire transfer, is the pattern usually filed as business email compromise — the same attack seen from the loss side rather than the technique side. If a targeted email arrives at a developer or an accounts-payable clerk, it is spear phishing. Escalate the target to the C-suite and it is whaling. One habit is worth carrying out of this activity. Several of these scenarios genuinely contain more than one technique — the uniform in the tailgating item is impersonation, the auditor pretext is delivered by voice, the whaling email is spear phishing. Real attacks chain techniques, and an exam question that offered every true label would have no answer. What is being tested, here and on the exam, is the ability to name the mechanism the attack depends on rather than every mechanism it touches. Ask what happens if you remove each element in turn; the one whose removal collapses the attack is the technique.

What you'll learn

Aligned to

CompTIA PenTest+
4.8 Given a scenario, perform social engineering attacks using the appropriate tools.
3.3 Explain physical security concepts.
CompTIA Security+
2.2 Explain common threat vectors and attack surfaces.
5.6 Given a scenario, implement security awareness practices.

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Pretexting
A social engineering technique in which an attacker fabricates a convincing scenario — such as impersonating IT support, a vendor, or an authority figure — to manipulate a target into performing an action or disclosing sensitive information.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Smishing
A social engineering attack delivered via SMS text messages that tricks recipients into clicking malicious links, calling fraudulent numbers, or revealing sensitive information such as account credentials or financial data.
Baiting
A social engineering technique that uses an enticing offer or lure to trick a victim into taking an action that compromises their security.
Tailgating
A physical security breach where an unauthorized person follows an authorized individual through a secured entry point without presenting credentials.
Quid Pro Quo
A social engineering attack technique involving an overt exchange of something for something, such as offering a benefit in return for access, credentials, or sensitive information.
Shoulder Surfing
An attack in which an adversary physically observes a victim entering credentials or access information by looking over their shoulder or from close proximity.
Whaling
A type of spear phishing attack that targets high-level executives or senior leadership within an organization, such as CEOs or C-suite members.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Piggybacking
A physical security attack where an unauthorized person follows an authorized person through a secured entry point with the authorized person's consent, typically by deceiving them.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →