Learning Objective 1.1.A: Identify common indicators of social engineering tactics.
- 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
- 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.
Learning Objective 1.1.B: Explain how social engineering tactics influence victims to perform a desired action.
- 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
- 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
- 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.
Learning Objective 1.1.C: Describe possible impacts for victims of social engineering attacks.
- 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
- 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
- 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.
학습 목표 1.1.A: 사회공학적 기법의 일반적인 징후를 식별하시오.
- 1.1.A.1 사회공학적 공격은 심리적 전략을 사용하여 사용자를 조작하여 민감한 정보(정보 유출)를 공개하게 하거나, 악의적 파일을 다운로드하거나, 악의적 링크를 클릭하게 합니다. 사회공학적 공격은 대면으로 수행되기도 하지만 주로 이메일, 문자 메시지 또는 소셜 미디어 메시지를 통해 이루어집니다.
- 1.1.A.2 적대자는自己的目标을 달성하기 위해 협박과緊迫감 같은 심리적 전략을 자주 사용합니다. 협박은 표적이 따르지 않을 경우 부정적인 결과를 초래한다고威胁하는 것입니다.緊迫감은 표적이 빠르게 행동해야 하는 이유를 만들어내는 것입니다.
학습 목표 1.1.B: 사회공학적 기법이 피해자를 특정 행동을 취하도록 유도하는 원리를 설명하시오.
- 1.1.B.1 사회공학적 기법은 인간의 행동을影响하는 일반적인 심리학적 원리에 의존합니다.
- 1.1.B.2 협박은 인간이 부정적인 결과에 자연적으로 회피하려는 성질을 이용합니다. 가능한 부정적인 결과를 강조함으로써 적대자는 공포를 유발하여 표적이 행동하도록 자극합니다.
- 1.1.B.3緊迫감은 시간이 제한된 필요에 대해 빠르게 반응하려는 인간의 본능적인 반응을 이용합니다. 표적이 메시지 내에緊迫감을 감지하면, 행동이 타당하거나 안전한지를 고려할 시간을 갖지 못해 빠르게 응답하거나 행동하도록 압박을 느끼게 됩니다.
학습 목표 1.1.C: 사회공학적 공격의 피해자가 겪을 수 있는 영향을 서술하시오.
- 1.1.C.1 피해자는 적대자에게 성명, 전화번호, 주소, 직장, 반려동물 이름 또는 생일 등 신원 위조(人身冒用)로 이어질 수 있는 개인 정보를 제공할 수 있습니다. 이러한 종류의 정보는 websites에서 사용자 신원을 확인하는Challenge 질문으로 자주 사용됩니다.
- 1.1.C.2 피해자는 적대자에게 일회용 비밀번호(OTP) 또는 인증 로그인 코드와 같은 보안 정보를 제공할 수 있으며, 이는 적대자가 피해자 명의로 서비스에 로그인할 수 있게 할 수 있습니다.
- 1.1.C.3 피해자는 악성 소프트웨어를 다운로드하거나, 악의적 링크를 클릭하여 장치에 악성 소프트웨어를 설치되거나, 웹 브라우저에서 정보를 도난당하거나,登录 credentials가 적대자에게 포획되는 웹사이트로 안내받을 수 있습니다.









