mediumMultiple Select
Social Engineering Attack Examples
Which TWO of the following are examples of social engineering attacks?
Quick Answer
The answer is phishing and shoulder surfing. These two are correct because social engineering attacks exploit human psychology and interaction rather than technical vulnerabilities, tricking people into revealing sensitive information or granting unauthorized access. Phishing uses deceptive emails or messages to lure victims into clicking malicious links or sharing credentials, while shoulder surfing involves directly observing someone’s screen or keystrokes to steal data. On the CompTIA ITF+ FC0-U61 exam, this question tests your ability to distinguish between human-focused attacks and purely technical ones like DDoS, brute force, or man-in-the-middle—a common trap is confusing phishing with technical exploits. A helpful memory tip: if the attack relies on tricking a person, not breaking a system, it’s social engineering.
⚠ Common exam trap
Many exam-takers confuse technical attacks like DDoS or brute force with social engineering, failing to recognize that social engineering specifically exploits human trust or behavior, not system vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shoulder surfing
Shoulder surfing (B) is a social engineering attack because it relies on directly observing a person—looking over their shoulder or using nearby cameras—to steal credentials, PINs, or other sensitive information through human interaction rather than technical exploitation. Phishing (E) is also social engineering since it manipulates a victim via deceptive emails, messages, or websites into revealing credentials or clicking malicious links, exploiting human trust rather than system vulnerabilities. By contrast, DDoS (A) is a network availability attack that floods a target with traffic, brute force (C) is a computational attack that systematically tries password or key combinations, and man-in-the-middle (D) is a network interception attack that relays or alters communications—none of these depend on psychologically manipulating a person, so they are not social engineering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DDoS
Why it's wrong here
A DDoS attack floods a target with traffic from many sources to exhaust its resources, relying on volume rather than deception. It is tempting because it also abuses legitimate systems, but no human is manipulated into revealing information or granting access, which is what defines social engineering.
- ✓
Shoulder surfing
Why this is correct
Shoulder surfing is a social engineering technique: the attacker observes a victim physically typing credentials or PINs, exploiting human behaviour rather than software flaws. It satisfies the stem's requirement for a social engineering example because no technical vulnerability is exploited — observation alone yields the information.
- ✗
Brute force
Why it's wrong here
Brute force is a computational attack that systematically tries every credential combination against an authentication service; it manipulates no human trust. It is tempting because it also targets credentials, but it belongs in the password-cracking category, whereas social engineering requires deceiving a person into revealing information or granting access.
- ✗
Man-in-the-middle
Why it's wrong here
Man-in-the-middle intercepts or relays network traffic between two parties, exploiting protocol or cryptographic weaknesses rather than human trust. It is tempting because it can capture credentials, but it operates at the network layer; social engineering instead manipulates a person into divulging information or performing an action.
- ✓
Phishing
Why this is correct
Phishing is a social engineering attack that manipulates the recipient into revealing credentials or clicking malicious links by impersonating a trusted entity. It satisfies the stem because the attack vector is human deception via email or messaging, not a software exploit.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on FC0-U71
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are examples of social engineering attacks?
easy- A.Adware
- B.Spoofing
- ✓ C.Tailgating
- ✓ D.Phishing
- ✓ E.Shoulder surfing
Why C: Tailgating (C) is a social engineering attack because it relies on manipulating a person's courtesy or trust to physically follow an authorized individual through a secure door or access point without presenting credentials. Phishing (D) is a social engineering attack that uses deceptive emails, messages, or websites to trick users into revealing credentials or clicking malicious links. Shoulder surfing (E) is a social engineering attack in which an attacker visually observes someone entering passwords, PINs, or other sensitive data in a public or shared space. Adware (A) is a type of unwanted software that displays advertisements and is classified as malware or a PUP, not a social engineering technique. Spoofing (B) is a technical impersonation technique, such as IP, MAC, or email spoofing, and while it can support social engineering, it is not itself an example of a social engineering attack.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.