Social Engineering and Phishing
Understand Social Engineering and Phishing for GCSE Computer Science with this free worksheet and full mark scheme — Foundation and Higher exam-style questions with worked answers for AQA GCSE Computer Science (8525). Social engineering tricks people into giving away information, for example through phishing emails.
Free downloads
These worksheets and mark schemes are original, written for Virtus Academy and checked against the current AQA specification. Every worksheet comes with a full mark scheme.
Topic overview
Social engineering means manipulating people into giving away information or access, rather than attacking technology directly.
Phishing is the most common form. The attacker sends emails or messages pretending to be a trusted organisation, directing the victim to a fake website that captures their login details. Warning signs include spelling errors, a generic greeting rather than the user's name, a sense of urgency, and a link whose actual address differs from the text shown.
Other forms include pretexting, where the attacker invents a scenario to justify their request, and shouldering, simply watching someone enter their password. Blagging and baiting work similarly. All exploit trust, helpfulness or fear rather than any technical weakness.
Revision notes
Phishing
Emails or messages pretending to be from a trusted organisation, directing the victim to a fake website.
The fake site captures the login details entered. The attacker then uses those credentials on the real site.
Recognising phishing
Spelling and grammar errors. A generic greeting rather than the user's name.
An artificial sense of urgency, such as a threat to close the account. A link whose actual address differs from the text displayed. Requests for information the organisation would already have.
Other social engineering
Pretexting: inventing a scenario to justify the request, such as pretending to be IT support.
Shouldering: watching someone enter their password. Baiting: leaving infected media where it will be found and used. All exploit trust rather than technology.
Key points
- Social engineering manipulates people.
- Phishing pretends to be a trusted organisation.
- Fake websites capture login details.
- Spelling errors are a warning sign.
- Urgency is used to prevent careful checking.
- Shouldering means watching someone type.
Worked examples
Example 1
Give two signs that an email may be a phishing attempt. [2 marks]
Working
Example 2
Explain how a phishing attack captures a user's password. [2 marks]
Working
Example 3
Explain why social engineering can succeed even against a well-protected system. [2 marks]
Working
Common mistakes
Saying phishing is a technical attack.
It exploits people, not software.
Giving only one warning sign.
Several are examinable.
Confusing phishing with malware.
Phishing captures credentials by deception; malware is software.
Forgetting shouldering and pretexting.
They are also social engineering.
Exam tips
- Learn several phishing warning signs.
- Explain the fake website mechanism.
- Name other social engineering forms.
- Stress that no technical weakness is exploited.
Key terms
- Social engineering
- Manipulating people into giving away information or access.
- Phishing
- Fraudulent messages capturing login details.
- Pretexting
- Inventing a scenario to justify a request.
- Shouldering
- Watching someone enter their credentials.
Related topics
Written and reviewed against the current AQA specification. Spotted an error? Let us know.