Social Engineering and Physical Security
Week of 2026-12-29 · Download .docx
Objectives
- Identify social engineering techniques including phishing, vishing, smishing, and pretexting
- Explain physical security controls including mantraps and badge access
- Describe proper data destruction methods and fire extinguisher classes
Key terms
- Phishing
- Fake emails impersonating trusted entities to steal credentials or deliver malware.
- Vishing
- Voice phishing — attacker calls impersonating IT, bank, or government to extract information.
- Smishing
- SMS phishing — malicious links or fake alerts sent via text message.
- Spear phishing
- Highly targeted phishing using personal details about the specific victim.
- Pretexting
- Creating a fabricated scenario and identity to manipulate a victim.
- Tailgating
- Following an authorized person through a secured door without badging in.
- Mantrap
- Two-door security vestibule preventing tailgating; first door closes before second opens.
- Cable lock
- Kensington-style lock securing a laptop to a fixed anchor point.
- Degaussing
- Exposing magnetic media to a powerful magnetic field to destroy all data.
- Secure Erase
- SSD firmware command overwriting all NAND cells to render data unrecoverable.
- Class C extinguisher
- For electrical fires — uses CO2 or dry chemical; never water on electrical fires.
- Badge reader
- Physical access control requiring authorized credential scan to enter secured areas.
The concept
SOCIAL ENGINEERING TECHNIQUES
Attackers exploit human psychology rather than software vulnerabilities. Phishing uses email; vishing uses voice calls; smishing uses SMS text messages. Spear phishing targets a specific individual using personal details (name, company, job title) harvested from social media to make the message more convincing. Pretexting constructs an elaborate false identity and backstory — posing as a vendor auditor or new IT contractor — to lower the victim's guard.
The most effective defense against social engineering is user education and verification procedures — always verify identities through a separate, known channel before sharing sensitive information or granting access.
PHYSICAL SECURITY CONTROLS
Tailgating exploits social politeness. The countermeasure is the mantrap (security vestibule or airlock) — a two-door entry system where authentication is required at each door and the first must close before the second opens. Badge reader systems with smart cards or RFID create an audit trail of every access event. Cable locks (Kensington locks) prevent opportunistic theft of laptops and mobile workstations by anchoring them to desks.
DATA DESTRUCTION
Simple deletion and formatting leave data fully recoverable. Proper disposal requires either physical destruction (shredding, crushing) or certified software overwriting. For HDDs, degaussing exposes the media to an intense magnetic field that randomizes all magnetic domains — the servo tracks are destroyed and the drive cannot function afterward. For SSDs, degaussing has no effect (no magnetic media) — use the drive's Secure Erase command instead. A certificate of destruction documents compliance.
FIRE SAFETY
Class C extinguishers (CO2 or dry chemical) are designed for electrical fires. Never use water (Class A) on electrical fires — water conducts electricity and creates severe electrocution risk. Class B covers flammable liquids; Class D is for combustible metals.
Worked examples
Common mistakes
- Confusing tailgating (physical access by following) with phishing (email credential theft).
- Quick-formatting a drive before disposal — data remains fully recoverable; use Secure Erase or physical destruction.
- Assuming degaussing works on SSDs — SSDs store data in NAND flash (not magnetic); degaussing has no effect on them.
- Confusing Class C (electrical) with Class A (ordinary combustibles) fire extinguishers.
- Thinking vishing and smishing are the same as phishing — medium matters: phone=vishing, SMS=smishing, email=phishing.
Self-check
Try each question before reading the answer. Answers at the bottom of this page.
1. Tailgating is:
- Following an authorized person through a secured door without badging in
- Calling and impersonating IT support
- Sending a targeted phishing email
- Attaching a USB to a computer
2. Vishing is social engineering conducted via:
- Voice calls (phone)
- SMS text message
- In-person deception
3. Which fire extinguisher class is used for electrical fires?
- Class C
- Class A
- Class B
- Class D
4. Which data destruction method uses powerful magnetic fields?
- Degaussing
- Secure Erase
- Quick Format
- Low-level format
5. A mantrap prevents:
- Tailgating
- Network intrusion
- Phishing attacks
- Portable device theft
Self-check answers
- 1. A — Tailgating exploits social courtesy to bypass physical access controls.
- 2. A — Vishing = voice phishing; attackers call impersonating IT, banks, or government.
- 3. A — Class C extinguishers use non-conductive CO2 or dry chemical — safe for electrical equipment.
- 4. A — Degaussing randomizes magnetic domains on HDDs; it has no effect on SSDs.
- 5. A — The two-door vestibule prevents a follower from entering with an authorized badge holder.
Canvas is the official record. This companion enhances the PGCC curriculum; it does not replace it. Last name and class year only. Students with a 504 plan or IEP: your accommodations apply.