Community resourceWorksheet
1CP2-P-5.3 Social engineering attacks
Part 3 of 6 · 1CP2-P-5 · Cyber security and robust software
The social engineering worksheet, covering the four required techniques and the point at which each manipulation chain can be broken.
Students will:
- identify the dominant technique in a described attack
- explain how a phishing attempt leads to unauthorised access
- identify warning signs in a pretexting call
- describe safe actions that break the manipulation chain
- compare social engineering with exploiting a technical vulnerability
Inside: 5 explanation cells, 5 multiple-choice questions, 1 fill-in-the-blanks cell and 5 written answers. 20 marks, about 45 minutes.
Series: 1CP2-P-5 · Cyber security and robust software, part 3 of 6.
Shared by Coding PathwayVerified teacher
- 16 cells
- About 45 minutes
- CC BY-SA 4.0
- Shared 17 Aug 2026
Preview
The whole resource, exactly as a class sees it. Answers and marking are held back.
Social engineering attacks
Social engineering manipulates people into revealing information, granting access or carrying out an unsafe action. Pearson's current guidance names phishing, pretexting, baiting and quid pro quo. The attacker exploits trust, urgency, fear, curiosity or expected reward rather than first exploiting code.
1. Four required techniques
The categories can overlap in real incidents, but examination scenarios usually provide a dominant mechanism. Identify the decisive clue: deceptive message, invented story, tempting bait, or promised exchange.
- baiting
- phishing
- pretexting
- quid pro quo
A message pretending to be the school portal directs staff to a fake sign-in page. Which technique dominates?
- ABaiting
- BPhishing
- CPretexting only
- DQuid pro quo
Explain how the phishing attempt could lead to unauthorised access.
Connect the fake page to credentials and later use.
Students type their answer here.
A caller claims to be a new technician and invents an urgent account-repair story to obtain a reset code. Which technique dominates?
- APretexting
- BBaiting
- CWorm
- DQuid pro quo
Identify two warning signs in the caller scenario.
Use the unexpected identity, urgency and requested secret.
Students type their answer here.
A labelled USB drive is left where a student may plug it in out of curiosity. Which technique dominates?
- APhishing
- BPretexting
- CBaiting
- DRansomware
A caller offers free technical support in return for the user's password. Which technique dominates?
- AQuid pro quo
- BWorm
- CBaiting
- DVirus
2. Break the manipulation chain
A safe response is to pause, refuse the requested secret or action, and verify through an independently obtained trusted channel. Do not use the phone number or link supplied by the suspicious contact. Report the attempt according to the organisation's procedure.
A student receives an urgent message asking them to sign in through a supplied link. Describe two safe actions.
Focus on stopping, independent verification or reporting.
Students type their answer here.
Compare social engineering with exploitation of an unpatched vulnerability.
State what is manipulated or exploited in each route.
Students type their answer here.
3. Build an examination explanation
A useful structure is: identify the technique → quote or paraphrase the scenario clue → explain the unsafe action → state the resulting risk. This prevents vague responses such as 'it is a scam because it looks suspicious'.
An attacker offers a free software upgrade if an employee first disables protection and shares a login code. Identify the main technique and explain the attack chain.
Use the promised exchange and resulting access risk.
Students type their answer here.
Which response best resists pretexting?
- ATrust anyone who knows the school name.
- BProvide only part of the password.
- CVerify the claimed identity through an independently known contact route.
- DReply to the same message asking if it is genuine.
Route forward
You can distinguish the four required social-engineering methods and explain their attack chains. Next you will select layered controls that protect confidentiality, behaviour and recovery.