Practice social engineering vocabulary for security awareness: phishing simulation, pretexting, vishing, attack chain language, and security awareness training communication.
0 / 12 completed
1 / 12
A security awareness trainer explains: "We ran a phishing simulation last month. 23% of employees clicked the link." What is a 'phishing simulation'?
Phishing simulations measure real susceptibility — not just self-reported awareness. Metrics tracked: open rate, click rate, credential submission rate. The gold standard: immediate teachable moment (employees who click see an educational page explaining what they missed), plus aggregate reporting to leadership. Simulation results drive training prioritisation: teams with high click rates get targeted awareness training.
2 / 12
A social engineering report mentions 'pretexting.' What does pretexting mean in this context?
Pretexting is the foundation of most social engineering: the attacker builds a believable story (pretext) to justify their request. Classic pretexts: 'I'm from IT, your account shows suspicious activity — I need to verify your credentials,' 'I'm a vendor auditor, I need access to the server room.' Pretexting exploits trust, authority, and helpfulness rather than technical vulnerabilities. It is used in both phishing emails and vishing calls.
3 / 12
A security report flags a 'vishing attempt targeting the finance team.' What is vishing?
Vishing (voice phishing) is telephone-based social engineering. Common scenarios: fake IT helpdesk calls requesting password resets, fake bank fraud alerts asking for card details, Business Email Compromise (BEC) paired with a phone call to authorise a wire transfer. Vishing is particularly effective against finance teams (BEC fraud) and customer service staff (SIM swapping). Defence: callback verification procedures, never act on unsolicited calls requesting sensitive actions.
4 / 12
A red team debrief describes a 'social engineering attack chain.' What does this term mean?
Attack chains show how individual social engineering techniques combine. No single step may be sufficient alone, but chaining them achieves the goal. Example: a spear-phishing email (step 1) installs a keylogger → credentials are captured (step 2) → an attacker calls the IT helpdesk using those credentials to add a new MFA device (step 3, pretexting as the employee) → full account takeover (step 4). Understanding attack chains helps defenders identify which link to break.
5 / 12
A security awareness training announcement reads: "This training helps prevent social engineering attacks by building a human firewall." What does 'human firewall' mean?
Technical controls (spam filters, MFA, endpoint detection) can be bypassed by targeting humans directly. The 'human firewall' concept recognises that security-aware employees are a critical defence layer. Training objectives: recognise phishing indicators, verify identity before acting on requests, report suspicious activity without fear, and follow procedures even when an 'authority figure' pressures them to skip steps. Simulation exercises + training build this firewall.
6 / 12
Sarah from the DevOps team sent a Slack message to Mark in Customer Support: 'Hey, I noticed a strange request – someone claiming to be our CEO wants us to urgently update the production database with this SQL query. It seems…off.' What technique is Sarah most likely encountering?
This scenario describes someone impersonating a high-authority figure (the CEO) to trick another team member. This is classic social engineering, where trust and authority are exploited. Options A, C, and D represent distinct cyberattacks with different methods – not this manipulative tactic.
7 / 12
David is reviewing a pull request for a new API endpoint. The PR description includes the phrase: 'We've leveraged social engineering to bypass authentication and gain access to sensitive data.' What does this statement *primarily* indicate about the vulnerability?
The phrase 'social engineering to bypass authentication' strongly suggests that an attacker tricked someone – likely a developer or user – into granting unauthorized access. This is a common approach where attackers exploit human trust and vulnerabilities in security processes, rather than exploiting technical flaws directly. Options A, C, and D represent other attack vectors.
8 / 12
Alex, a security analyst, sent a Slack message to the development team: 'Someone posing as our CTO just emailed requesting immediate access to all AWS S3 buckets. They claim they need to 'verify backups.' What tactic is being described here?
Pretexting involves fabricating a situation or story to convince someone to divulge information or take action. This message clearly describes someone inventing a reason (verifying backups) to gain unauthorized access, aligning perfectly with the definition of pretexting. Options A and B represent different attack methods; Doxing is about revealing personal data, not initiating access.
9 / 12
During a standup meeting, Liam from the Security team says: 'We're conducting a 'honeypot' exercise. We've set up a fake server with deliberately vulnerable credentials to lure attackers and observe their methods.' What does a 'honeypot' represent in this context?
A honeypot is a deliberately vulnerable system created to *attract* malicious activity. The goal isn't to protect real assets but to observe attacker behavior and gather intelligence about their tactics. This contrasts with the other options which describe different security tools or protective measures – it's designed for observation, not prevention.
10 / 12
You're reviewing a pull request from Ben that includes the following comment: 'To streamline the deployment process, we utilized 'social engineering' to convince the database server to accept our new configuration without formal approval.' What does this suggest about the approach taken?
The phrase 'social engineering' in this context strongly indicates an effort to manipulate a system or process—likely by exploiting vulnerabilities or bypassing established controls. This is a common tactic used in social engineering attacks and represents a deviation from standard security practices. It suggests a lack of proper authorization and control.
11 / 12
A team lead, Chloe, is documenting a recent incident in the incident response report: 'The attacker successfully impersonated a senior developer to gain access to the internal Jira instance and escalate privileges.' What type of social engineering technique is primarily illustrated here?
Impersonation involves pretending to be someone you're not to achieve a specific goal. In this case, the attacker successfully imitated a senior developer to gain access and elevate privileges within Jira. This is a core element of many social engineering attacks, leveraging trust and authority.
12 / 12
During a training session, the instructor explains: 'A 'waterhole attack' involves gaining access to an organization by befriending an employee and then exploiting their trust.' What does this describe?
A 'waterhole' attack represents an approach where attackers gain entry by establishing a relationship with a trusted individual within the target organization. By befriending this person, they can then exploit that trust to access systems or data – mirroring the concept of social engineering's reliance on human interaction and vulnerability. This contrasts with DoS attacks which focus on overwhelming resources.
What will I practise in "Social Engineering Vocabulary"?
This module focuses on Pentest Communication — real workplace phrasing you'll use on the job. It contains 12 scenario-based multiple-choice questions with instant feedback.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account or sign-up required.
How many questions does this exercise have?
This module includes 12 questions. Each one gives an immediate right/wrong result plus a full explanation of the correct phrasing.
What happens if I answer a question incorrectly?
You'll see the correct answer highlighted straight away, along with a plain-English explanation of why it's right and why the other options don't fit — mistakes are part of the learning here.
Can I retry the exercise if I want a better score?
Yes — use the 'Try again' button on the results screen to reset your score and go through the questions again. There's no limit on attempts.
Who is this Pentest Communication exercise for?
It's aimed at IT professionals with working English who want to sound more natural and precise around pentest communication — useful whether you're preparing for real conversations at work or just building confidence with the vocabulary.
Do I need an account to track my progress?
No account is needed. Your progress through the exercise is tracked locally in your browser for the current session, and you can replay the module at any time.
How is this different from reading a blog article?
This exercise is an interactive drill that tests and reinforces specific phrasing through multiple-choice questions with instant feedback, while blog articles explain concepts and vocabulary in prose. The two work well together.
Where can I find more Pentest Communication exercises?
See the Pentest Communication hub for more modules like this one, or browse the full Exercises page for other IT-English topics.
Can I complete this exercise on my phone?
Yes — every exercise on CoderSlingo is fully responsive and works on phones and tablets, so you can practise anywhere.