Phishing, blagging, baiting, shouldering — attacking people rather than systems. A guaranteed topic on Component 1. Sourced from Craig 'n' Dave Topic 5 slides.
—
Best score
—
Last attempt
Best attempt progress
0
XP earned
Watch first — Craig 'n' Dave
Craig 'n' Dave · Edexcel 1CP2Social Engineering Attacks
Key facts
Social engineering — attacking people, not computers
Social engineering is the art of manipulating people so they give up confidential information
It exploits human psychology (trust, fear, curiosity) rather than technical vulnerabilities
Often the easiest way into a secure system — people are the weakest link
Types of social engineering attack
Phishing — sending emails pretending to be from reputable companies to trick users into revealing passwords or personal data. Spear phishing = targeted at a specific person.
Blagging (pretexting) — creating a fabricated scenario to manipulate a victim. E.g. pretending to be IT support to get a password.
Baiting — offering something enticing (free music/movies, a USB labelled "Confidential") to trick a victim into installing malware or revealing information.
Shouldering (shoulder surfing) — physically observing someone entering a PIN, password or sensitive data.
Preventing social engineering
Staff training — teach employees to recognise attack techniques
Verify identity — always check who you are talking to before sharing information
Email filters — block suspicious emails before they reach users
Clear screen policy — prevent shoulder surfing by locking screens
USB restrictions — disable autorun, restrict unauthorised USB devices
Security culture — never share passwords, even with colleagues
Exam questions — 5 questions · 12 marks
⚡ This module includes extended questions (4–6 marks). Read the hint. Write in full linked sentences. The AI will tell you exactly which mark scheme points you missed.
1 markPhishing definitionEdexcel 1CP2 style
Which of the following best describes a phishing attack?
A Physically watching someone enter their PIN number
B Sending emails pretending to be from a reputable source to trick users into revealing personal information
C Leaving a USB drive in a public place hoping someone will plug it in
D Calling someone pretending to be IT support to obtain their password
1 markBlaggingEdexcel 1CP2 style
A cybercriminal calls a company employee pretending to be from the IT helpdesk and asks for their password to "fix an urgent problem". What type of attack is this?
A Phishing
B Baiting
C Shouldering
D Blagging (pretexting)
4 marksExplain a phishing attackEdexcel 1CP2 style
Describe how a phishing attack works and explain two technical measures a company could use to reduce the risk of phishing attacks being successful. (4 marks)
Hint: Describe the attack (how it works, what the attacker does, how the victim is tricked). Then give two specific technical measures — not just "educate staff".
+40 XP
1 markBaitingEdexcel 1CP2 style
A USB drive labelled "Staff Salaries — Confidential" is left in a company car park. An employee picks it up and plugs it into their work computer. What type of attack is this?
A Phishing
B Blagging
C Baiting
D Shouldering
4 marksCompare technical and social engineering attacksEdexcel 1CP2 style
Explain why social engineering attacks are often more effective than purely technical attacks, and describe how organisations can defend against them. (4 marks)
Hint: Explain WHY humans are the weakest link (psychology over technology). Then give at least two defences — must go beyond just saying "train staff" and explain what the training should cover.