Skip to content
VirtusAcademy

Social Engineering and Phishing

FoundationHigherAQA

Understand Social Engineering and Phishing for GCSE Computer Science with this free worksheet and full mark scheme — Foundation and Higher exam-style questions with worked answers for AQA GCSE Computer Science (8525). Social engineering tricks people into giving away information, for example through phishing emails.

Free downloads

These worksheets and mark schemes are original, written for Virtus Academy and checked against the current AQA specification. Every worksheet comes with a full mark scheme.

Topic overview

Social engineering means manipulating people into giving away information or access, rather than attacking technology directly.

Phishing is the most common form. The attacker sends emails or messages pretending to be a trusted organisation, directing the victim to a fake website that captures their login details. Warning signs include spelling errors, a generic greeting rather than the user's name, a sense of urgency, and a link whose actual address differs from the text shown.

Other forms include pretexting, where the attacker invents a scenario to justify their request, and shouldering, simply watching someone enter their password. Blagging and baiting work similarly. All exploit trust, helpfulness or fear rather than any technical weakness.

Revision notes

Phishing

Emails or messages pretending to be from a trusted organisation, directing the victim to a fake website.

The fake site captures the login details entered. The attacker then uses those credentials on the real site.

Recognising phishing

Spelling and grammar errors. A generic greeting rather than the user's name.

An artificial sense of urgency, such as a threat to close the account. A link whose actual address differs from the text displayed. Requests for information the organisation would already have.

Other social engineering

Pretexting: inventing a scenario to justify the request, such as pretending to be IT support.

Shouldering: watching someone enter their password. Baiting: leaving infected media where it will be found and used. All exploit trust rather than technology.

Key points

  • Social engineering manipulates people.
  • Phishing pretends to be a trusted organisation.
  • Fake websites capture login details.
  • Spelling errors are a warning sign.
  • Urgency is used to prevent careful checking.
  • Shouldering means watching someone type.

Worked examples

Example 1

Give two signs that an email may be a phishing attempt. [2 marks]

Working

Spelling or grammar errors, and a generic greeting rather than the user's namegive the first two signs
An artificial sense of urgency, or a link whose actual address differs from the text showngive further signs

Example 2

Explain how a phishing attack captures a user's password. [2 marks]

Working

The email directs the victim to a fake website that looks like the real onestate the method
and when the victim enters their login details, those details are captured by the attackerexplain the capture

Example 3

Explain why social engineering can succeed even against a well-protected system. [2 marks]

Working

It exploits people's trust and helpfulness rather than any technical weaknessstate the mechanism
so technical protections are bypassed entirely when a user gives away their credentials voluntarilyexplain why protections fail

Common mistakes

  • Saying phishing is a technical attack.

    It exploits people, not software.

  • Giving only one warning sign.

    Several are examinable.

  • Confusing phishing with malware.

    Phishing captures credentials by deception; malware is software.

  • Forgetting shouldering and pretexting.

    They are also social engineering.

Exam tips

  • Learn several phishing warning signs.
  • Explain the fake website mechanism.
  • Name other social engineering forms.
  • Stress that no technical weakness is exploited.

Key terms

Social engineering
Manipulating people into giving away information or access.
Phishing
Fraudulent messages capturing login details.
Pretexting
Inventing a scenario to justify a request.
Shouldering
Watching someone enter their credentials.

Written and reviewed against the current AQA specification. Spotted an error? Let us know.