← Back to course

Identity, Authentication, and Social Engineering

You’ll be able to

Identity, Authentication, and Social Engineering

Authentication factors are something you know, have, or are. Multifactor authentication combines different factor types. Social engineering bypasses technical defenses by manipulating people, so verification procedures and low-friction reporting are as important as filters.

Decision lens

Strong technical decisions connect evidence → mechanism → impact → response. Identify what the evidence shows, explain the system behavior that produced it, state the likely effect on people or data, and choose a response that addresses the cause without creating unnecessary disruption.

Worked example

A caller claiming to be IT asks a teacher to read back a push-notification code so an urgent update can finish.

  1. 1.The caller creates urgency and claims authority.
  2. 2.The code is a possession-factor approval, not harmless troubleshooting information.
  3. 3.The teacher should end the call and contact IT through a known channel.
  4. 4.IT should review sign-in logs and revoke suspicious sessions.
Answer: Treat the request as likely social engineering; never approve or disclose an unsolicited authentication challenge.
Checkpoint

Which pair is truly multifactor?

Checkpoint

Which response best demonstrates complete reasoning about identity proof, authentication factors, and social engineering?

On the exam

For a scenario about identity proof, authentication factors, and social engineering, identify the decisive evidence before naming a response. A defensible conclusion here is: Treat the request as likely social engineering; never approve or disclose an unsolicited authentication challenge.

Answer the 2 checkpoints as you read.

Sign in to save your progress