Certified: The CompTIA Security+ Audio Course
Episode 43: Human Vectors and Social Engineering (Part 2) (Domain 2)
15 Jun 2025
While basic social engineering relies on message-based deception, more advanced techniques target identity, credibility, and digital presence through impersonation, pretexting, and domain spoofing. In this episode, we examine how attackers craft elaborate backstories or scenarios to manipulate users into granting access, exposing data, or clicking on malicious content. Business Email Compromise (BEC) attacks impersonate executives or vendors to request fraudulent wire transfers, while watering hole attacks poison websites frequently visited by specific organizations or industries. Typosquatting and brand impersonation further blur the line between legitimate and malicious sites, exploiting subtle changes in URLs to fool users. These attacks often bypass traditional security controls by exploiting trust and familiarity, making user vigilance and domain protection strategies essential. We explore how technical defenses like SPF, DKIM, and DMARC support email authenticity and how training can build resistance to persuasion techniques. Defending against these threats means understanding both the attacker’s psychology and the user’s blind spots.
No persons identified in this episode.
This episode hasn't been transcribed yet
Help us prioritize this episode for transcription by upvoting it.
Popular episodes get transcribed faster
Other recent transcribed episodes
Transcribed and ready to explore now
3ª PARTE | 17 DIC 2025 | EL PARTIDAZO DE COPE
01 Jan 1970
El Partidazo de COPE
13:00H | 21 DIC 2025 | Fin de Semana
01 Jan 1970
Fin de Semana
12:00H | 21 DIC 2025 | Fin de Semana
01 Jan 1970
Fin de Semana
10:00H | 21 DIC 2025 | Fin de Semana
01 Jan 1970
Fin de Semana
13:00H | 20 DIC 2025 | Fin de Semana
01 Jan 1970
Fin de Semana
12:00H | 20 DIC 2025 | Fin de Semana
01 Jan 1970
Fin de Semana