mediumMultiple SelectObjective-mapped
Social Engineering Attack Examples
Which TWO of the following are examples of social engineering attacks?
Quick Answer
The answer is phishing and shoulder surfing. These two are correct because social engineering attacks exploit human psychology and interaction rather than technical vulnerabilities, tricking people into revealing sensitive information or granting unauthorized access. Phishing uses deceptive emails or messages to lure victims into clicking malicious links or sharing credentials, while shoulder surfing involves directly observing someone’s screen or keystrokes to steal data. On the CompTIA ITF+ FC0-U61 exam, this question tests your ability to distinguish between human-focused attacks and purely technical ones like DDoS, brute force, or man-in-the-middle—a common trap is confusing phishing with technical exploits. A helpful memory tip: if the attack relies on tricking a person, not breaking a system, it’s social engineering.
⚠ Common exam trap
Many exam-takers confuse technical attacks like DDoS or brute force with social engineering, failing to recognize that social engineering specifically exploits human trust or behavior, not system vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shoulder surfing
Shoulder surfing is a social engineering attack where an attacker directly observes a user's screen or keyboard to capture sensitive information like passwords or PINs. It relies on human behavior rather than technical vulnerabilities, making it a classic example of social engineering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DDoS
Why it's wrong here
A DDoS attack overwhelms a server with traffic, not social engineering.
- ✓
Shoulder surfing
Why this is correct
Shoulder surfing involves observing a user's screen or keyboard to capture information.
- ✗
Brute force
Why it's wrong here
A brute force attack attempts many password combinations, typically automated.
- ✗
Man-in-the-middle
Why it's wrong here
MITM intercepts communications, often technical rather than social.
- ✓
Phishing
Why this is correct
Phishing uses deceptive emails or messages to trick users into revealing credentials.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on FC0-U71
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are examples of social engineering attacks?
easy- A.Adware
- B.Spoofing
- ✓ C.Tailgating
- ✓ D.Phishing
- ✓ E.Shoulder surfing
Why C: Tailgating (option C) is a social engineering attack where an unauthorized person follows an authorized individual into a restricted area. Shoulder surfing (option E) is a social engineering attack where an attacker observes a victim's screen or keyboard to obtain sensitive information. Phishing (option D) is a social engineering attack that uses deceptive emails or websites to trick users into revealing personal information. All three rely on psychological manipulation or human behavior. Adware (option A) is a type of malware, and spoofing (option B) is a technical attack involving impersonation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.