Free Social Engineering Attacks, Threats, and Vulnerabilities practice questions
10 free 220-1202 questions on Social Engineering Attacks, Threats, and Vulnerabilities, each with a full explanation — no account needed. This section sits in the Security part of the exam. Answer every question to see your score, then read the lessons below for anything you missed.
A secure area uses RFID badges for door access. Staff report that people regularly slip in behind an employee who has just badged through, before the door closes, without that employee noticing and without scanning a badge of their own. Which term describes this behavior?
Tailgating is following an authorized person through a controlled door without their knowledge, so the reader never sees a second badge and the entry is tied to nobody. Piggybacking is the same physical act but with the badge holder's consent, such as holding the door for a stranger, which the stem rules out by saying the employee does not notice. Impersonation is pretending to be someone else to gain access, and shoulder surfing is watching someone enter a PIN or password.
A user at a coffee shop connects to a Wi-Fi network named 'CoffeeShopWiFi' and is immediately asked to enter their email password to 'verify access.' After submitting, the page reloads and asks again, and the browser then shows a certificate warning on a site that normally loads fine. Which type of attack is MOST likely occurring?
This is an evil twin attack, where an attacker sets up a rogue access point that matches the SSID of a trusted network to trick devices into connecting. Once connected, the attacker can present a fake captive portal that harvests credentials and proxy traffic, which explains the repeated login prompts and unexpected certificate warnings. These trust and stability clues are classic evil twin indicators. A distributed denial of service floods a target with traffic from many sources to make a service unavailable; it does not steal credentials through a fake portal. A zero-day exploit targets a software vulnerability that has no vendor fix yet and would not present itself as a Wi-Fi login page. Dumpster diving involves searching physical trash for sensitive information such as password lists or network diagrams and has nothing to do with a wireless connection. The combination of a look-alike SSID, a credential-harvesting portal, and certificate warnings points clearly to an evil twin rather than any of the other options.
An employee receives a text message claiming to be from a shipping carrier: 'Package held due to address error. Update now: [link].' The message creates urgency and includes a shortened link. Which type of social engineering attack is this?
Smishing is phishing delivered through SMS text messages or messaging apps. Attackers rely on short, urgent prompts with a link because it is difficult to inspect a link's true destination on a small mobile screen, encouraging quick action. A fake delivery notice with a link fits this pattern exactly. Vishing is voice phishing conducted over phone calls or voicemail, where an attacker might ask a victim to read out a code or verify account details verbally, not through a text link. Whaling targets high-value individuals such as executives, finance staff, or HR, usually to redirect payments or steal sensitive employee data, and this generic delivery message is not aimed at a specific high-impact role. Shoulder surfing is an in-person attack in which someone observes a screen or keyboard to capture passwords or PINs, requiring physical proximity rather than a text message. Because the delivery method here is an SMS text with a malicious link, the correct classification is smishing.
A help desk technician receives a phone call from someone claiming to be from the internal service desk. The caller says an MFA failure locked the user's account and asks the user to read back the one-time code they just received. What is the BEST response?
This is a vishing attempt, and the safest response is to hang up and call the help desk using a verified number from the official company directory, then report the number and the request. Legitimate support staff never need your one-time passcodes, so any request to read a code aloud is a major red flag. Reading the code so the account can be unlocked quickly hands the attacker the exact second factor they need to complete a login, which is the entire goal of the call. Staying on the line while logging in lets the attacker control the moment and pressure you into further mistakes; a common attacker tactic is to keep the victim engaged during the compromise. Forwarding the code by email still exposes the code to the attacker and does nothing to verify the caller's legitimacy. The consistent defense pattern for social engineering is to avoid interacting through the attacker's channel, verify through a trusted one, and report the attempt so others are protected.
A company's public website suddenly becomes unreachable. Firewall logs show a massive volume of inbound traffic originating from thousands of different IP addresses across many geographic locations, while the server's CPU and memory usage remain normal. Which attack is MOST likely occurring?
A distributed denial of service (DDoS) attack uses many sources at once, often a botnet of infected devices, to overwhelm a target. The key clues are large traffic from many IP addresses across many locations and saturated bandwidth even though server health metrics like CPU and memory look normal, indicating the network link is full rather than the server being overloaded. A plain DoS attack originates from a single main source or path, so it would not show thousands of distinct IP addresses spread across many locations. An on-path attack places an attacker between the victim and the destination to read, modify, or redirect traffic; it targets confidentiality and integrity rather than causing a mass availability outage from many sources. Spoofing fakes the identity of a sender, site, or caller to trick users into risky actions and does not by itself flood a service with traffic. Because the defining characteristic here is overwhelming traffic from many distributed sources causing an availability failure, DDoS is the correct answer.
While walking toward a badge-controlled server room, a technician is approached by a person carrying boxes who says, 'My badge isn't working, can you hold the door for me?' Which action BEST addresses the security risk?
This scenario describes tailgating, where an unauthorized person attempts to follow an authorized user through a secured door by relying on social pressure and politeness. The safest and most defensible response is to decline entry, direct the person to reception or security to verify their access, and report the attempt with a description and location. Holding the door because the person appears busy is exactly the social pressure attackers exploit; a fake badge and full hands are common props to make the request feel reasonable. Asking the person to swipe again does not solve the problem if their credentials are invalid or fake, and it still risks granting unauthorized access. Lending your badge is a serious violation of access control that directly enables the breach and removes all accountability, since access would be logged under your identity. The correct habit is to put verification ahead of politeness, escort or redirect unverified individuals, and report the incident.
Security researchers just announced a newly discovered vulnerability in a widely used VPN client, and there is currently no vendor fix available. Attackers are already exploiting it. Which action is the MOST appropriate immediate response for the support team?
This describes a zero-day situation, indicated by the phrases 'newly discovered' and 'no vendor fix available.' When no patch exists, the correct approach is to use compensating controls that reduce the chance of a successful exploit and limit damage, such as disabling the vulnerable feature, restricting access to the affected service, and using network segmentation. Waiting for the vendor patch while continuing normal operations leaves the weakness fully exposed during the most dangerous window, when attackers are already exploiting it. Resetting all user passwords does not address the underlying software vulnerability and could waste effort while the exploit remains reachable; password resets belong later and only after containment. Reimaging every affected workstation is disruptive, does not remove a flaw that still exists in the software, and would be reintroduced the moment the vulnerable client is reinstalled. The proper zero-day mindset focuses on containment and compensating controls to buy time until a reliable fix is released, then treating that patch as urgent under change control.
An accounts payable employee receives an email that appears to come from the CEO: 'Need you to wire $48,600 to the new account for the acquisition. I'm in meetings, confirm when sent.' The message pressures for fast action and bypasses normal approval. Which type of attack is this?
This is business email compromise (BEC): an attacker impersonates a trusted executive by email to pressure a finance employee into sending money to an attacker-controlled account. The defining elements are a forged or look-alike trusted sender, urgency, and a request that bypasses the normal approval process to reroute a payment. Whaling is phishing that targets the executive as the victim rather than impersonating them; spear phishing is a targeted phishing email in general, and BEC is the specific form aimed at fraudulent payments; QR code phishing (quishing) uses a malicious QR code rather than an email request.
A user reports repeated certificate warnings across multiple trusted websites, frequent session drops requiring re-authentication, and being redirected to a login page they did not request. These symptoms appeared after joining an unfamiliar network. Which attack BEST explains these combined symptoms?
An on-path attack (formerly man-in-the-middle) places the attacker between the device and the sites it talks to, usually through a rogue access point, ARP spoofing, or DNS manipulation on the network the user just joined. Because the attacker must intercept or re-sign traffic, the clues appear together: certificate warnings on sites that are normally fine, sessions dropping so the user re-authenticates, and redirects to login pages nobody asked for. A denial of service causes timeouts and slowness, not certificate errors and redirects. A brute-force attack generates failed sign-in attempts against an account and produces no symptoms in the victim's browser. SQL injection targets a web application's database through crafted input and would not affect every trusted site the user visits.
A user notices a QR code sticker on a parking kiosk labeled 'Scan to pay.' The sticker appears to be placed over another label with peeling edges and mismatched branding. What is the BEST security practice in this situation?
This is a QR code phishing (quishing) scenario, where an attacker places a malicious code that routes to a fake payment page. The tampered sticker with peeling edges and mismatched branding is a classic tell that a legitimate code has been covered by a fraudulent one. The safest practice is to avoid scanning a random or suspicious code and instead use an official app or type the address yourself, which prevents you from landing on an attacker-controlled site. Scanning the code because kiosks are routine ignores the visible tampering and the fact that you cannot preview a QR code's destination the way you might hover over a link. Entering only partial card details still submits sensitive data to a potentially fraudulent page and offers no real protection. Peeling off the sticker to scan the code underneath assumes the underlying code is legitimate, which is unverified, and still risks scanning an untrusted destination. QR codes should be treated like shortened links: you cannot judge safety by appearance, so verify the destination or use a trusted app.
Study this section
Every lesson that covers Social Engineering Attacks, Threats, and Vulnerabilities on the 220-1202 exam.
Free PBQs for this section
Interactive performance-based questions on Social Engineering Attacks, Threats, and Vulnerabilities, graded instantly.