Phishing & Social Engineering
Social engineering manipulates human cognitive biases rather than exploiting hardware flaws to breach secure systems. Threat actors deploy targeted vectors such as spear phishing against corporate executives, voice-based vishing, and SMS-driven smishing to execute unauthorized credential harvesting. These deceptive communications impersonate trusted banking portals, government departments, or enterprise administrators using homograph domain spoofing and forged cryptographic certificates. Defensive architectures rely on multi-factor authentication (MFA) via FIDO2 hardware tokens, DMARC email authentication protocols, and strict identity verification workflows. In modern competitive examinations, questions assess threat classification, social manipulation techniques, and preventative authentication protocols.
Key Concepts & Examination Highlights
- Spear phishing targets specific individuals using tailored personal information, distinguishing it from untargeted mass phishing campaigns.
- Vishing utilizes voice telephone communications and VoIP spoofing, whereas smishing exploits SMS channels to deliver malicious links.
- DMARC (Domain-based Message Authentication, Reporting, and Conformance) prevents email spoofing by verifying SPF and DKIM records.
- FIDO2 authentication standards enforce public-key cryptography via hardware tokens to prevent credential harvesting attacks.