A+ Lesson

Social Engineering Attacks and Phishing Variants for A+

Last updated: 6/10/2026

Short answer

Social engineering uses human trust and routine to bypass technical controls. Phishing variants change only the delivery channel (email, phone, SMS, QR) or the targeting level (spear, whaling). Physical social engineering exploits presence and access behaviors (shoulder surfing, tailgating, dumpster diving). Technicians should identify indicators, advise verification steps, and escalate suspicious requests rather than perform deep incident remediation.

Why it appears on the exam

- Identify which delivery channel a sample message uses and name the phishing variant. - Recognize a physical access scenario and determine whether it is tailgating or impersonation. - Choose verification steps a technician should take when a user reports a suspected phishing link.

Key concepts

Concept 1

Required terms

phishing: Fraudulent messages (usually email) designed to trick recipients into revealing credentials, clicking malicious links, or providing sensitive data. vishing: Voice-based phishing where attackers call or use voicemail to trick victims into revealing information or performing actions. smishing: SMS/text-based phishing that uses text messages to lure recipients into clicking links or revealing data. QR code phishing: Using malicious QR codes (printed or on-screen) that direct users to spoofed sites or trigger unintended actions.

Example

Email from 'IT' asking you to click a link and re-enter your password (phishing).

Concept 2

How Social Engineering Attacks and Phishing Variants works

Social engineering uses human trust and routine to bypass technical controls. Phishing variants change only the delivery channel (email, phone, SMS, QR) or the targeting level (spear, whaling). Physical social engineering exploits presence and access behaviors (shoulder surfing, tailgating, dumpster diving). Technicians should identify indicators, advise verification steps, and escalate suspicious requests rather than perform deep incident remediation.

Example

Text message with a short link about a missed delivery (smishing).

Concept 3

Common confusion

People often treat any unsolicited security prompt as legitimate, especially if it imitates familiar language. Another confusion is equating spear phishing with generic phishing; the difference is personalization and intent. Technicians must verify through out-of-band methods (call the sender, check official portals) rather than rely on message content alone.

Example

Call claiming to be from the help desk asking for a one-time code (vishing).

Concept 4

Core 2 (220-1202) question cues

Identify which delivery channel a sample message uses and name the phishing variant; Recognize a physical access scenario and determine whether it is tailgating or impersonation; Choose verification steps a technician should take when a user reports a suspected phishing link.

Example

A visitor following an employee into a secure area claiming they lost their badge (tailgating).

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.An A+ support scenario describes this situation: Email from 'IT' asking you to click a link and re-enter your password (phishing). Which answer fits best?

Q2.A support ticket includes this clue: Call claiming to be from the help desk asking for a one-time code (vishing). Which concept is being tested?

Q3.Read this A+ scenario: Text message with a short link about a missed delivery (smishing). Which term or action matches it?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8