Let's think about this for a second
Pretexting — the attacker poses as IT support, a boss, or a vendor to request information (for example, 'This is IT, we need to verify your password'). Baiting — dangling a 'free USB drive' or an attractive download to plant malware. Tailgating — following an authorized person into an office building. CEO fraud/Business Email Compromise — posing as the CEO to demand an urgent wire transfer.
Let's connect this to a real scenario
If someone calls claiming to be 'IT Support' and asks for your password — real IT support will never ask for your password over the phone or email. If you get a sensitive request (a money transfer, a password, access), call back through an official channel (a number you look up yourself) to verify — never use the number the caller gave you (it could be fake).
Let's walk through it together
Social engineering red flags
-----------------------------
"ကျွန်တော် IT ကနေပါ, password confirm ဖို့လိုပါတယ်"
"CEO က urgent wire transfer တောင်းနေပါတယ်, ဒီနေ့ပဲ လုပ်ပေးပါ"
"ဒီ USB drive ကို free ဖြန့်ဝေနေပါတယ်"You'll be able to distinguish four social engineering techniques and describe a defense for each.Try it in 5 minutes
Write your own scenario where someone poses as a 'boss' or 'IT support' with an urgent request, then write down how you should respond.
A quick word of caution
Never use a 'callback number' the attacker gives you — look up the number yourself from the company's official website and verify it.