Social Engineering and Human Factors
Phishing, pretexting, insiders
Social Engineering and Human Factors target people, not machines: phishing, pretexting, and manipulation that bypass technical controls. Defending it means awareness, process, and a healthy dose of skepticism.
Why Social Engineering and Human Factors matters
People are the target
Most breaches start with a human clicking, not a firewall failing.
Bypasses tech controls
A convincing pretext can defeat MFA and policy through the person in the loop.
Awareness pays off
Trained, skeptical users are the cheapest and strongest last line of defense.
What you'll practice
Quizzes and spaced repetition keep these sharp, reinforcement not a replacement for deep study.
- Recognize phishing, spear-phishing, and BEC
- Recall common pretexting and baiting tactics
- Tell legitimate requests from manipulation
- Keep insider-threat indicators fresh
- Spot urgency and authority pressure cues
Topics covered
Social engineeringHuman factorsPhishing and spear-phishingInsider threatsZero Trust Human
A peek at the format
PreviewMultiple Choice
What distinguishes spear-phishing from generic phishing?
AIt targets a specific, researched individual
BIt only uses phone calls
CIt never uses email
DIt always requires malware
This is a preview. Create an account to actually play.
Play for realRelated certifications
- SANS SEC467
- CompTIA Security+
- EC-Council CEH
- GIAC GSLC