课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Social engineering

Social engineering

- [Narrator] Digital threats aren't the only issue facing information security professionals seeking to protect their organizations. Some of the most dangerous risks come from the human threat of social engineering. These are also some of the hardest threats to defend against. Social engineering attacks use psychological tricks to manipulate people into performing an action or divulging sensitive information that undermines the organization's security. For example, an attacker posing as a help desk technician might use social engineering to trick a user into revealing their password over the telephone. Social engineering attacks are the online version of running a con. There are six main reasons that social engineering attacks are successful. These include authority, intimidation, consensus, scarcity, urgency, and familiarity. Let's dig into each of these a little more. Psychological experiments have shown consistently that people will listen and defer to someone who is conveying an…

内容