TechKnowSurge
CompTIA Security+ 2.2 CompTIA Network+ 4.2 CompTIA Security+ 5.6
InteractiveSecurityFree

Social Engineering Technique Identifier

Sort social engineering scenarios into Phishing, Smishing, Vishing, Baiting, Tailgating or Quid Pro Quo.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Social engineering works on a person instead of a machine, and every attack in this activity has to reach its victim somehow. That is the first question to ask about each scenario: how did it reach them? If it arrived as a message, the channel names it. An email is phishing, a text message is smishing (SMS is how texts travel, which is where the S comes from), and a phone call is vishing (voice phishing). The words inside the message do not change that. A caller with a very convincing story about being from the IT department is still vishing, because the phone is how the attack reached you. The story is a pretext, a fabricated reason to trust the caller, and almost every one of these attacks uses one. A targeted email that names your boss and a real vendor is spear phishing, which is still phishing, just with homework done first. If the attack did not arrive as a message, name the trick. Baiting leaves something tempting where the victim will find it, such as a USB drive labelled with salary data or a free download, and waits for curiosity to do the rest. Nobody has to talk to the victim at all. Tailgating is physical: following someone through a door they unlocked, often by looking like you belong there or by having your hands full. Quid pro quo means something for something. A person offers the victim a trade, such as a gift card, a free gadget or cash, in exchange for information or access. Baiting and quid pro quo both offer the victim something, so they are the easiest pair to mix up. The difference is whether a person is making a deal with you. A USB drive on the floor makes no deal; a stranger offering you a gift card for your password does.

What you'll learn

Aligned to

CompTIA Security+
2.2 Explain common threat vectors and attack surfaces.
5.6 Given a scenario, implement security awareness practices.
CompTIA Network+
4.2 Summarize various types of attacks and their impact to the network.

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Smishing
A social engineering attack delivered via SMS text messages that tricks recipients into clicking malicious links, calling fraudulent numbers, or revealing sensitive information such as account credentials or financial data.
Pretexting
A social engineering technique in which an attacker fabricates a convincing scenario — such as impersonating IT support, a vendor, or an authority figure — to manipulate a target into performing an action or disclosing sensitive information.
Baiting
A social engineering technique that uses an enticing offer or lure to trick a victim into taking an action that compromises their security.
Tailgating
A physical security breach where an unauthorized person follows an authorized individual through a secured entry point without presenting credentials.
Quid Pro Quo
A social engineering attack technique involving an overt exchange of something for something, such as offering a benefit in return for access, credentials, or sensitive information.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Whaling
A type of spear phishing attack that targets high-level executives or senior leadership within an organization, such as CEOs or C-suite members.

Topics

Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →