From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,200 courses taught by industry experts.

Social engineering

Social engineering

- Social engineering attacks. In this lesson, we're going to focus on the different types of social engineering attacks, including phishing, tailgating, piggybacking, shoulder surfing, eavesdropping, and dumpster diving. Now, before we get into the specific attacks, let's define social engineering. Social engineering is any attempt to manipulate users into revealing confidential information or performing other actions that are detrimental to that user or the security of our systems. Social engineering is always focused on the human element and trying to find a way to bypass our system's technical controls by simply hacking the human instead of hacking the technology. For example, if I wanted to break into your wireless network and I found that you had implemented a long, strong password for your WPA2 AES encrypted network, it could take me years upon years to brute force that password. But if I instead figure out a way to trick you or your users into sharing that password with me, I…

Contents