ISTQB Mock App

Social Engineering

Social engineering is the manipulation of people into revealing confidential information or performing actions that compromise security.

Official definition
ISTQB Official Glossary Definition
An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Social Engineering?

Attackers exploit trust, curiosity, fear, or urgency rather than technical vulnerabilities to achieve their objectives.

Human-focused attack: Targets people instead of software.

Psychological manipulation: Exploits human behavior.

Security awareness: Training helps reduce risk.

Real World Example

A regulated product team is preparing a release where Social engineering appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.

The risk is that the team treats Social engineering as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.

The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between Social engineering and similar ideas.

The page becomes useful in practice because Social engineering is connected to a specific testing decision, not memorized as a detached definition.

Practice Questions

Question 1

Which statement BEST describes Social engineering in the context of ISTQB terminology?

Question 2

A tester needs to explain Social engineering to a non‑technical stakeholder. Which approach is MOST appropriate?

Test your knowledge with real ISTQB-style questions

You’ve learned Social Engineering. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams