Identity, Authentication, and Social Engineering
- Explain identity proof, authentication factors, and social engineering
- Apply the idea to evidence from a realistic technology scenario
- Justify a decision using security, reliability, cost, and user impact
Identity, Authentication, and Social Engineering
Authentication factors are something you know, have, or are. Multifactor authentication combines different factor types. Social engineering bypasses technical defenses by manipulating people, so verification procedures and low-friction reporting are as important as filters.
Decision lens
Strong technical decisions connect evidence → mechanism → impact → response. Identify what the evidence shows, explain the system behavior that produced it, state the likely effect on people or data, and choose a response that addresses the cause without creating unnecessary disruption.
A caller claiming to be IT asks a teacher to read back a push-notification code so an urgent update can finish.
- 1.The caller creates urgency and claims authority.
- 2.The code is a possession-factor approval, not harmless troubleshooting information.
- 3.The teacher should end the call and contact IT through a known channel.
- 4.IT should review sign-in logs and revoke suspicious sessions.
Which pair is truly multifactor?
Which response best demonstrates complete reasoning about identity proof, authentication factors, and social engineering?
For a scenario about identity proof, authentication factors, and social engineering, identify the decisive evidence before naming a response. A defensible conclusion here is: Treat the request as likely social engineering; never approve or disclose an unsolicited authentication challenge.
Answer the 2 checkpoints as you read.
Sign in to save your progress