Impersonation is one of the most foundational social engineering techniques on the Security+ exam: pretending to be a trusted person or entity so that borrowed trust does the work of getting cooperation. The attacker doesn't break a system — they just need the victim to believe the role they're playing, whether that's IT support, a bank, a vendor, or a senior executive.
This video gives you the one mental model — assume a trusted identity, then let that trust drive compliance — and the fingerprints the exam uses: a false trusted identity, borrowed authority that pushes the victim to comply, a goal of information, access, or an action, and the fact that impersonation usually rides inside another technique. The core of the video is the distinction the exam tests most — impersonation is the identity you assume, while pretexting is the fabricated story you tell — and the recognition that impersonation can be a correct answer alongside the channel, so a payroll-spoofing text is both phishing and impersonation. We map how impersonation underpins pretexting, vishing, business email compromise, and brand impersonation, then finish with the defenses the exam rewards: verifying identity through a separate trusted channel, strict verification procedures, awareness training, least privilege, and MFA. A rapid-fire drill locks it in.
By the end you will recognize impersonation on sight, separate it from pretexting, and see it as the engine inside much of the social engineering family.
Subscribe for the full Security+ series working through every domain the same way.