Social Engineering Attacks and Phishing Variants for A+
Short answer
Social engineering uses human trust and routine to bypass technical controls. Phishing variants change only the delivery channel (email, phone, SMS, QR) or the targeting level (spear, whaling). Physical social engineering exploits presence and access behaviors (shoulder surfing, tailgating, dumpster diving). Technicians should identify indicators, advise verification steps, and escalate suspicious requests rather than perform deep incident remediation.
Why it appears on the exam
- Identify which delivery channel a sample message uses and name the phishing variant. - Recognize a physical access scenario and determine whether it is tailgating or impersonation. - Choose verification steps a technician should take when a user reports a suspected phishing link.
Key concepts
Concept 1
Required terms
phishing: Fraudulent messages (usually email) designed to trick recipients into revealing credentials, clicking malicious links, or providing sensitive data. vishing: Voice-based phishing where attackers call or use voicemail to trick victims into revealing information or performing actions. smishing: SMS/text-based phishing that uses text messages to lure recipients into clicking links or revealing data. QR code phishing: Using malicious QR codes (printed or on-screen) that direct users to spoofed sites or trigger unintended actions.
Example
Email from 'IT' asking you to click a link and re-enter your password (phishing).
Concept 2
How Social Engineering Attacks and Phishing Variants works
Social engineering uses human trust and routine to bypass technical controls. Phishing variants change only the delivery channel (email, phone, SMS, QR) or the targeting level (spear, whaling). Physical social engineering exploits presence and access behaviors (shoulder surfing, tailgating, dumpster diving). Technicians should identify indicators, advise verification steps, and escalate suspicious requests rather than perform deep incident remediation.
Example
Text message with a short link about a missed delivery (smishing).
Concept 3
Common confusion
People often treat any unsolicited security prompt as legitimate, especially if it imitates familiar language. Another confusion is equating spear phishing with generic phishing; the difference is personalization and intent. Technicians must verify through out-of-band methods (call the sender, check official portals) rather than rely on message content alone.
Example
Call claiming to be from the help desk asking for a one-time code (vishing).
Concept 4
Core 2 (220-1202) question cues
Identify which delivery channel a sample message uses and name the phishing variant; Recognize a physical access scenario and determine whether it is tailgating or impersonation; Choose verification steps a technician should take when a user reports a suspected phishing link.
Example
A visitor following an employee into a secure area claiming they lost their badge (tailgating).
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.An A+ support scenario describes this situation: Email from 'IT' asking you to click a link and re-enter your password (phishing). Which answer fits best?
Q2.A support ticket includes this clue: Call claiming to be from the help desk asking for a one-time code (vishing). Which concept is being tested?
Q3.Read this A+ scenario: Text message with a short link about a missed delivery (smishing). Which term or action matches it?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8