Social engineering attacks are one of the most dangerous threats in cybersecurity — not because they exploit software vulnerabilities, but because they exploit people. If you’re preparing for the ISC2 CC or ISC2 SSCP exam, understanding how attackers manipulate human psychology is essential. Both exams test your ability to identify attack types, explain how they work, and recommend appropriate defenses. Let’s break down exactly what the exam expects you to know — and how to think like a security professional when you encounter these scenarios.
What Is Social Engineering?
Social engineering is the art of manipulating individuals into revealing confidential information or performing actions that compromise security. Unlike brute-force attacks that target systems directly, social engineering targets the weakest link in any security chain: human behavior. Attackers exploit trust, authority, fear, urgency, and curiosity to bypass even the most sophisticated technical controls.
The ISC2 CC exam (exam code CC, 100 questions, 3 hours, passing score 700/1000) covers social engineering within its Security Concepts domain. The ISC2 SSCP exam (125 questions, 3 hours, passing score 700/1000) goes deeper, testing your ability to design countermeasures. Both exams require more than memorizing attack names — you need to understand why each attack works.
Common Types of Social Engineering Attacks
Phishing, Spear Phishing, and Whaling
Phishing is the most prevalent social engineering attack. An attacker sends a fraudulent email designed to look legitimate — mimicking a bank, cloud provider, or internal IT team — to trick the recipient into clicking a malicious link or revealing credentials. Key characteristics include spoofed sender addresses, urgent language, and lookalike domains (e.g., paypa1.com instead of paypal.com).
Spear phishing is a targeted variant. Instead of blasting thousands of generic emails, the attacker researches a specific individual — using LinkedIn, company websites, or social media — and crafts a highly personalized message. This dramatically increases success rates.
Whaling takes spear phishing further by targeting high-value individuals like CEOs, CFOs, or IT directors. A whaling email might impersonate legal counsel demanding an urgent wire transfer. The ISC2 exams expect you to distinguish between these three and identify which controls mitigate each.
Vishing and Smishing
Not all social engineering happens over email. Vishing (voice phishing) uses phone calls to impersonate IT helpdesks, banks, or government agencies. An attacker might call an employee claiming to be from the IT department and request their password to
Ready to Pass Your Certification?
Practice with 1,890 expert-written questions across 17 CompTIA, ISC2, AWS, and Cisco exams.
Free to start, no credit card required.