Social Engineering Prevention
Recognize manipulation in person, on the phone and online, and verify before you act
- Duration
- 1.5 hours
- Modules
- 4
- Final exam
- 70% to pass
- Certificate
- No expiry
- Lifetime access to the course and your certificate
- Verifiable Certificate of Completion. Certificate does not expire.
- 3 exam attempts
- Progress saved to your account on every slide
Buying for a team? Volume pricing from 5 seats
| 1 to 4 seats | List price |
| 5 to 10 seats | 15% off |
| 11 to 20 seats | 25% off |
| 21 or more seats | 35% off |
$250.75
5 × $50.15 · save $44.25
Each seat is a single-use code. Send one to each learner; they sign in with their own account and earn their own certificate. Track progress on your Team page.
About this course
Social engineering is the art of getting people to do what an attacker wants: hold a door, reset a password, read out a code, plug in a drive, share a shipping schedule or let a stranger into the stockroom. It needs no malware. It needs a convincing story and a person who wants to be helpful. At a defense supplier, that story is aimed at controlled unclassified information, export-controlled drawings, payments and physical access to the shop floor.
This course shows you how the manipulation works, from the psychology attackers rely on to the full attack cycle of research, approach, exploitation and exit. It walks through the techniques you will meet: pretexting as a helpdesk, vendor or executive; voice and text phishing; tailgating; baited USB drives; quid pro quo; on-site impersonation; dumpster diving; shoulder surfing; and the oversharing on social media and job sites that gives attackers their script.
You will then build the habits that defeat these techniques: verification by a known number, visitor control and badges, challenging politely, clean desk, information classification, what you may and may not say on the phone, and the physical protection controls that sit behind the badge reader. Realistic scenarios give you a decision to make in each.
The course is awareness-level training for every employee of a company that handles federal contract information or CUI. It supports NIST SP 800-171 Rev 2 requirements 3.2.1 and 3.2.2 and the CMMC Awareness and Training domain, and it explains why internal reporting in minutes matters to the company's 72-hour DoD reporting duty under DFARS 252.204-7012. Follow your own company's procedures and security officer. The course closes with a 10-question examination drawn from a bank of 20. On passing you receive a PlanetISO Certificate of Completion with lifetime access. The certificate does not expire.
What you will be able to do
- Explain the psychological levers social engineers use: authority, urgency, reciprocity, familiarity and fear.
- Describe the social engineering attack cycle from reconnaissance to exit and recognise the stage you are in.
- Identify pretexting, vishing, smishing, tailgating, baiting, quid pro quo, impersonation, dumpster diving and shoulder surfing.
- Apply verification habits, including calling back on a known number and escalating when a request resists verification.
- Follow visitor control, badge, clean desk and information classification practices and explain the requirements behind them.
- State what you may and may not disclose on the phone, in person and online about your company's work.
- Decide the correct action in realistic scenarios and report attempts through the company's reporting path.
Course outline
- 1
How manipulation works
The levers social engineers pull, the attack cycle from reconnaissance to exit, and why a helpful person at a defense supplier is the target.
About 20 minutes, then a module quiz
- 2
The techniques you will meet
Pretexting as helpdesk, vendor or executive; vishing and smishing; tailgating and piggybacking; baited USB drives; quid pro quo; on-site impersonation; dumpster diving; shoulder surfing; and oversharing online.
About 20 minutes, then a module quiz
- 3
Defences you can use today
Verification habits, calling back on a known number, visitor control and badges, challenging politely, clean desk, information classification, what to say on the phone, and the physical protection controls behind the badge reader.
About 20 minutes, then a module quiz
- 4
Scenarios and reporting
5 situations with a decision to make, the reporting path, what to include in a report, and how reporting supports the company's DFARS 72-hour obligation.
About 25 minutes, then a module quiz
Final examination and certificate
10 questions drawn from the course bank. Score 70% or higher to receive your Certificate of Completion.
More CMMC and NIST SP 800-171 training
- CMMC and NIST SP 800-171Short course
CMMC Level 2 and NIST SP 800-171 Overview
What a Level 2 assessment expects, how the 110 requirements are organized and how to build a program that passes
- Duration
- 3 hours
- Level
- Foundation
$99View course - CMMC and NIST SP 800-171Awareness
Insider Threat Awareness
Recognize and report the indicators that protect your colleagues, your company and controlled information
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
Phishing and Email Security
Spot the message that is trying to trick you, and know exactly what to do next
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
CUI Handling and Marking
Recognize controlled unclassified information, mark it correctly and handle it safely
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
CMMC Level 1 Overview
The 15 basic safeguards for federal contract information and how the annual self-assessment works
- Duration
- 1.5 hours
- Level
- Foundation
$59View course