Social engineering manipulates people—not software—into revealing credentials or wiring money. Phishing is email/message driven.
Red flags
- Urgent tone, mismatched sender domain
- Unexpected attachments or login links
- Requests to bypass process "just this once"
Defenses
Security training, phishing simulations, MFA, email filtering, verify out-of-band for wire transfers.
Important interview questions and answers
- Q: Spear phishing?
A: Targeted email using personal details. - Q: Vishing?
A: Voice phishing—fake IT support calls.
Self-check
- Name two phishing red flags.
- How MFA helps against stolen passwords?
Tip: Report phishing buttons in company mail—early reporting limits spread.
Interview prep
- MFA vs phishing?
Reduces account takeover from stolen passwords.