📖 What is Social Engineering?

Social Engineering manipulates individuals into performing actions or divulging confidential information. Attackers exploit human psychology, trust, and vulnerabilities to bypass security measures. Techniques include pretexting, baiting, quid pro quo, and tailgating, often used in conjunction with technical attacks.

🥋 Sensei Says:

"The exam tests your ability to identify social engineering tactics and recommend preventative measures. Focus on user awareness training, strong password policies, and multi-factor authentication as mitigation strategies. Understand the difference between physical and digital social engineering attacks."

📚 Certification: CompTIA A+ Certification Exam Core 2 (220-1102)

🔑 What are the Key Concepts of Social Engineering?

  • Pretexting involves creating a fabricated scenario to trick victims into revealing information or granting access, often relying on trust.
  • Baiting uses the promise of something desirable (like a free download) to lure victims into a malicious trap, often involving malware.
  • Phishing, a common tactic, uses deceptive emails, websites, or messages to steal credentials or sensitive data by impersonating legitimate entities.
  • Tailgating exploits physical security by following authorized personnel into restricted areas without proper authentication.
  • User awareness training is the most effective countermeasure, educating users to recognize and report suspicious activity.

🎯 How does Social Engineering appear on the 220-1102 Exam?

You may be asked to identify which scenario represents a social engineering attack, differentiating it from a technical exploit like a virus or brute-force attack.

A scenario might describe an employee receiving a phone call from 'IT support' requesting their password – determine the correct course of action to prevent compromise.

Expect questions about recommending preventative measures to a small business owner concerned about their employees falling victim to phishing scams.

❓ Frequently Asked Questions

How can I differentiate between phishing and spear phishing?

Phishing is a mass email campaign, while spear phishing is highly targeted, often referencing personal information to appear legitimate and increase success rates. Both aim to steal credentials.


What's the role of multi-factor authentication (MFA) in preventing social engineering attacks?

MFA adds an extra layer of security beyond just a password. Even if an attacker obtains credentials through social engineering, they still need the second factor to gain access.


Is social engineering only a digital threat?

No, social engineering encompasses both digital and physical attacks. Physical examples include tailgating, dumpster diving, and shoulder surfing, all aiming to gain unauthorized access.

Related Terms from CompTIA A+ Certification Exam Core 2

📝 Related Study Guides

Study Guide 10 min read

CompTIA A+ Core 2 (220-1102): How to Pass and Study Plan

To pass the CompTIA A+ Core 2 (220-1102) exam, you must score at least 700/900. Focus on the four key domains: Operating Systems (31%), Security (25%), Software Troubleshooting (22%), and Operational Procedures (22%). Success requires mastering OS command lines, security protocols, and a systematic troubleshooting methodology through rigorous practice exams.

Comparison 7 min read

NTFS vs FAT32 vs exFAT: A+ Core 2 File System Guide

NTFS is the Windows standard featuring security permissions and journaling. FAT32 offers maximum compatibility but limits individual files to 4GB. exFAT bridges the gap, removing the 4GB limit while maintaining cross-platform support for flash drives. Choosing the right one depends on the required security, file size, and OS compatibility.

Study Guide 8 min read

CompTIA A+ Core 2 (220-1102): Domains, Tips & Study Plan

To pass the CompTIA A+ Core 2 (220-1102) exam, you must master four domains: Operating Systems (31%), Security (25%), Software Troubleshooting (22%), and Operational Procedures (22%). Success requires a score of 700/900. The best strategy combines hands-on OS practice, understanding security protocols, and solving 1,000+ high-quality practice questions to build exam stamina.

🧠

Test Your Knowledge

Think you understand Social Engineering? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium