Skip to main content

Unit 1 · Topic 1.1

1.1 Understanding Social Engineering

Social engineering means hacking the person instead of the computer: an attacker uses psychology to get you to share information, open a file or click a link. This topic teaches you to spot two of the biggest pressure tactics, intimidation and urgency, and to explain what a victim can lose when they fall for them.

Key terms

  • social engineering
  • phishing
  • elicitation
  • intimidation
  • urgency
  • one-time password (OTP)

What social engineering is

Social engineering is any attack that manipulates a person into doing what the attacker wants. Instead of breaking through a firewall, the attacker gets you to open the door. The goal is usually one of three things: getting you to reveal sensitive information, getting you to download a harmful file, or getting you to click a harmful link.

Getting information out of someone through conversation is called elicitation. A friendly stranger who asks where you work, what your dog's name is and when your birthday is might just be chatty, or might be collecting answers to your account's security questions.

Social engineering can happen face to face, but it usually arrives through email, text messages or social media messages. A scam email is called phishing. You may also hear smishing (by text) and vishing (by voice call), but the exam focuses on the tactics, not the channel names.

Two pressure tactics: intimidation and urgency

Attackers lean on normal human instincts. Two show up constantly.

Intimidation is a threat: do this, or something bad happens. It works because people naturally want to avoid negative consequences, and fear pushes them to act before they think. Examples: "Your account will be suspended," "You'll be reported to the police," "Your grade will be withheld."

Urgency is a time limit: do this right now. It works because people react fast to anything that feels time-sensitive, and that rush skips the step where you ask, "Does this make sense?" Examples: "within 30 minutes," "by the end of the day," "final notice."

Many scams use both at once, like "Pay within 24 hours or your service will be shut off." On the exam, separate them: the deadline is urgency, and the threatened consequence is intimidation.

What a victim can lose

  • Personal details that let someone impersonate you: name, phone number, address, workplace, pets' names, birthdate. Many websites use exactly these as challenge questions to confirm who you are, so giving them away can let an attacker reset your password.
  • A one-time password (OTP) or login code. That code is the second step that proves you are you. If you read it to someone, they can log in as you, even if they don't know your password.
  • Malware. Opening an attachment or clicking a link can install software that takes over your device or steals data saved in your web browser, like saved passwords and cookies.
  • Your password itself. A link can lead to a fake login page that looks real and captures whatever you type.

How to protect yourself

  • Treat pressure as a warning sign. A real bank, school or employer can wait while you check.
  • Verify through a separate channel. Call the number on the back of your card or type the website address yourself instead of using the link or number in the message.
  • Never share a one-time code with anyone who contacts you. Legitimate support staff don't need it.
  • Before clicking, check where a link really goes. Look at the host name (the part before the first single slash) and read it from the right. In login.example.com.account-check.example.net, the site belongs to example.net, not example.com; everything to the left is just labels the owner of example.net chose. (Some country addresses use three parts for the owner's name, like example.co.uk.)
  • Report suspicious messages so others can be warned.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Picking apart a scam text

    You get this text: "Northfield Credit Union ALERT: suspicious sign-in detected. Your account will be FROZEN in 30 minutes. Reply with the 6-digit code we just sent you to keep access." Identify the urgency and the intimidation in the message, and describe the most likely impact if you reply.

    Show the solution
    1. Step 1: Find the deadline. "in 30 minutes" pressures you to act right away. That is urgency.
    2. Step 2: Find the threatened consequence. "Your account will be FROZEN" warns of something bad if you don't comply. That is intimidation.
    3. Step 3: Ask what the attacker actually wants: the 6-digit code. A code that arrives by text right after someone tries to sign in is a one-time password.
    4. Step 4: Connect the request to the impact. The attacker probably already has your password and triggered the code by trying to log in. If you send the code, they can finish logging in as you.

    Answer: Urgency: "in 30 minutes." Intimidation: "Your account will be FROZEN." If you reply, the attacker gets your one-time login code and can sign in to your account as you.

  2. Example 2

    Spotting elicitation

    A new account on a social app messages you: "Hey! I'm making a birthday calendar for our grade. What's your birthday? And what was your first pet's name, for a fun fact?" Explain why this could be a social engineering attack.

    Show the solution
    1. Step 1: Notice that the message asks for specific personal details instead of offering anything. Collecting information through friendly conversation is elicitation.
    2. Step 2: Look at which details: birthdate and first pet's name. Both are common challenge questions used to verify identity or reset a password.
    3. Step 3: Explain the impact: with those answers, an attacker could pass your account's security questions and take it over, or use the details to impersonate you.

    Answer: It's elicitation: the questions collect a birthdate and first pet's name, which are common security-question answers, so the attacker could use them to reset your password or pretend to be you.

Common mistakes

  • Mixing up urgency and intimidation. Urgency is about time ("by 5 p.m."); intimidation is about a threatened consequence ("or you'll lose access"). Quote the exact phrase that matches the tactic the question names.
  • Thinking a one-time code is safe to share because it expires. It's dangerous precisely because it's valid right now, which is all the attacker needs.
  • Assuming social engineering only happens by email. It also happens by text, social media, phone and in person.
  • Describing the impact vaguely ("they could hack you"). Name the specific result: impersonation, account login with your code, malware on your device, or a captured password.

On the exam

  • Expect a short message or email as a source, followed by questions like which phrase shows urgency, which shows intimidation, or what the most likely impact of replying would be.
  • When asked for an impact, match it to what the message requests: personal details lead to impersonation, a code leads to account takeover, and a link or attachment leads to malware or a fake login page.

Connected topics

Videos

  • AP Cybersecurity Topic 1.1 - Understanding Social Engineering. Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Phishing - CompTIA Security+ SY0-701 - 2.2

    Professor MesserWatch on YouTube (opens in a new tab)

  • Social Engineering in Under 3 mins (AP Cybersecurity Unit 1 Topic 1) 1.1

    Maximum InsightWatch on YouTube (opens in a new tab)

  • Phishing attacks | Internet safety | Khan Academy

    Khan AcademyWatch on YouTube (opens in a new tab)

  • AP Cybersecurity Topic 1.1: Social Engineering — Full Lesson Walkthrough

    AP CS Exam PrepWatch on YouTube (opens in a new tab)

  • What is Phishing

    IBM TechnologyWatch on YouTube (opens in a new tab)

Check yourself: 1.1 Understanding Social Engineering

4 questions on 1.1 Understanding Social Engineering. Pick an answer to see if you got it, and why.

From: Maple Ridge HS IT Service Desk <helpdesk@mapleridge-accounts.example.net>

To: All Students

Subject: ACTION REQUIRED: Verify your student account

Our system shows that your student account has not been verified for the new semester. This verification link expires at 3:00 p.m. TODAY.

Students who ignore this notice will be reported to the assistant principal and will lose access to their grades and assignments.

To verify, go to https://mapleridge-accounts.example.net/verify, sign in with your school username and password, and then type the 6-digit code that we text to your phone.

Thank you for helping keep our network safe!

Maple Ridge IT Service Desk

An email reported to the IT department of Maple Ridge High School, an invented school whose real domain is mapleridge.example.org

Question 1 of 4

Which part of the email uses intimidation to pressure students?

Question 2 of 4

Why might the 3:00 p.m. deadline make a student more likely to follow the email's instructions?

Question 3 of 4

A student follows the instructions and types the 6-digit code from the text message into the site. Which is the most likely impact?

Question 4 of 4

Which detail in the email is the strongest sign that the link does not lead to a real school site?

0 of 4 answered