Browse all practice questions for the Understanding Cyber Attacks: Phishing and Social Engineering Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Understanding Cyber Attacks: Phishing and Social Engineering Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What personal information might vishing attackers try to obtain?
  • What is the primary goal of vishing?
  • How do scammers typically use social media in their attacks?
  • Which statement about drive-by downloads is true?
  • Whaling attackers commonly target which roles?
  • Which set describes message-based attacks?
  • Which statement about brand impersonation and trust is true?
  • What are message-based attacks?
  • How does vishing typically use VoIP technology?
  • What is phishing?
  • Which statement about the impact of spam on productivity is true?
  • What is the classic Nigerian scam (419 scam)?
  • What is a drive-by download?
  • What is a common tactic used in phishing emails to entice users to click a link?
  • What is a potential consequence of a successful whaling attack?
  • Whaling attacks masquerade as complaints from which entities to gain executive attention?
  • What is the main method attackers use to send spear phishing emails?
  • Which of the following is NOT listed as commonly targeted by SPIM?
  • Which statement best helps prevent phishing-like attacks?
  • What is the primary goal of brand impersonation?
  • What is the potential risk if a user responds to a smishing text?
  • What is a recommended defense against brand impersonation attacks?
  • What is whaling in cybersecurity?
  • Which of the following is a common method criminals use to obtain email addresses for spam?
  • What action should you take when you encounter a suspicious email about your account?
  • What is a common tactic used by criminals in phishing attacks?
  • What is a recommended method for verifying the identity of someone requesting sensitive information?
  • Which security feature helps verify the sender's identity in email messages?
  • Give an example of a common pretexting scenario.
  • Which technology is used to spoof caller ID in vishing?
  • What is the typical goal when a phishing email includes a malicious link?
  • What was a notable whaling attack involving Seagate?
  • Which of the following illustrates a common pretexting scenario?
  • Which statement best describes spear phishing?
  • Drive-by malware is primarily enabled by which action?
  • What happens when a user clicks a malicious link in a phishing email?
  • How do attackers use compromised servers in their attacks?
  • What is the significance of digital signatures in email security?
  • What should you remember about spam and phishing?
  • What should you do if you receive a suspicious vishing call?
  • Which technique is used to harvest credentials?
  • If you receive a suspicious email about your account, what is the safest course of action?
  • What distinguishes spear phishing from regular phishing?
  • How do attackers benefit from obtaining personal information through vishing?
  • What should users do if they receive suspicious texts or emails?
  • Which statement best describes pretexting?
  • What role does social engineering play in cyberattacks?
  • Why are high-level executives referred to as 'whales' in whaling attacks?
  • What is bracketing in information elicitation?
  • How can brand impersonation exploit consumer trust?
  • Brand impersonation often relies on which tactic?
  • Another COVID-19 scam targeted individuals seeking what for a fee?
  • What is vishing?
  • What is a common example of a brand impersonation attack?
  • When verifying identity for sensitive information requests, which practice is recommended?
  • Why might a phishing email include an attachment that looks like a photo?
  • What is a drive-by download?
  • What should employees be educated about to minimize the risks of email attacks?
  • What do victims of the Nigerian scam often end up doing?
  • What is brand impersonation in the context of cyber attacks?
  • What is spear phishing?
  • What is vishing?
  • What types of individuals might an attacker impersonate in a pretexting attack?
  • What is smishing?
  • In a drive-by download phishing scheme, what typically happens when you visit the page?
  • What is the main difference between spam and phishing?
  • In phishing campaigns, attackers often prompt users to take what action that leads to malware installation?
  • Which statement best describes spear phishing?
  • Give an example of a smishing attack.
  • Why might attackers purchase similar domain names?
  • Which scenario best illustrates elicitation in social engineering?
  • Which statement best describes how reflective questioning is used in social engineering?
  • What is the impact of spam on productivity?
  • Smishing is phishing conducted via
  • Which organizations have experienced whaling attacks?
  • Which of the following is a prudent step when you suspect a text or email is fraudulent?
  • Which statement describes the role of digital signatures in email security?
  • Which of the following is required by law for companies sending marketing emails?
  • Which of the following is a classic example of a phishing attack?
  • Which statement defines a drive-by download?
  • How do attackers typically request money in phishing scams?
  • If you receive an email claiming to be from a famous company asking you to revalidate credentials via a link, what should you do?
  • What is a potential consequence of opting out of a mailing list?
  • Which statement best describes smishing?
  • Which organization might whaling impersonate to gain executive attention?
  • What best describes SPIM?
  • Which of the following best describes what attackers can do with information obtained from a successful phishing attack?
  • What might attackers do with information gathered through elicitation?
  • What is a common tactic used by vishing attackers involving credit cards?
  • What is the effect of attention during a conversation in social engineering?
  • What is a botnet in the context of phishing?
  • What should you be wary of when you receive emails related to social media interactions?
  • What is a recommended safe practice to reduce phishing risk?
  • What is reflective questioning?
  • What role does trust play in brand impersonation attacks?
  • What is the effect of attackers' full attention during a conversation in social engineering?
  • Which strategy helps reduce brand impersonation risk?
  • What is the relationship between botnets and phishing emails?
  • Which statement about smishing is true?
  • One COVID-19 related scam involved a message that claimed you had contact with someone who tested positive and included what?
  • What is the role of digital signatures in combating spear phishing?
  • What is a common tactic used by attackers when purchasing a domain with a slight misspelling of a legitimate site?
  • Which tactic would attackers use to make a malicious website appear legitimate?
  • Which line is commonly used in phishing emails to entice clicking a malicious link?
  • How might an attacker use a fake website in a brand impersonation scenario?
  • Vishing uses which channel?
  • What is the purpose of the phishing email with the subject 'We have hijacked your baby'?
  • Which phrase is a common urgency tactic used in phishing emails?
  • Which practice helps reduce risk from phishing attempts?
  • What personal information do scammers often attempt to obtain?
  • What is phishing?
  • How do beacons work in phishing emails?
  • Credential harvesting often involves which practice?
  • What type of information could attackers potentially gather after phishing?
  • Why is user education important in preventing cyberattacks?
  • Digital signatures in email communications primarily help recipients verify what?
  • How do attackers typically disguise malicious websites?
  • Which of the following best describes whaling's target audience?
  • Why do attackers purchase similar domain names?
  • What is a common security issue related to social media?
  • What is the significance of the phrase 'We have noticed suspicious activity on your account' in phishing emails?
  • Which scenario illustrates the common whaling tactic of impersonation?
  • Why do spam emails often include opt-out instructions?
  • How can SPIM bypass typical security measures?
  • What is a common response from vishing attackers when asked to stop calling?
  • Which outcome is not typically listed as a potential impact of a cyberattack?
  • What common strategy do vishing attackers use to appear legitimate?
  • Which risk is commonly associated with social media impersonation through forged emails?
  • What measures can organizations take to defend against pretexting attacks?
  • What is the impact of social engineering techniques on cybersecurity?
  • What is a common consequence of brand impersonation phishing emails?
  • Vishing is a phishing attack conducted over the
  • What is a drive-by malware attack?
  • Which of the following is not a tactic used by criminals in phishing attacks?
  • What is spam in the context of email?
  • Which of the following is NOT a characteristic of elicitation in social engineering?
  • Which of the following best describes a hallmark of spear phishing?
  • What is a common distraction used in phishing emails during a drive-by download?
  • Drive-by download description?
  • Why do most email programs not display images by default?
  • What is the purpose of the malicious link in phishing emails?
  • Which organizations have experienced whaling attacks?
  • What can happen if a user clicks on a malicious link in a spear phishing email?
  • Which statement about the impact of social engineering on cybersecurity is true?
  • What might be a consequence of brand impersonation for victims?
  • Which statement about whaling is true?
  • What is the purpose of using a malicious link in an email?
  • Which of the following are examples of message-based attacks?
  • What is the purpose of a phishing email?
  • What is the main goal of phishing emails?
  • How can attackers exploit smishing?
  • SPIM is characterized by real-time communication delivered via which channel?
  • What is a key characteristic of phishing emails?
  • What can the information obtained from phishing enable attackers to do?
  • What best describes spear phishing?
  • How can you identify the actual sender of an email that appears to be from a friend?
  • What is typical content of a phishing email designed to install malware?
  • What is one solution to deter spear phishing attacks?
  • What is the relationship between social engineering and cybersecurity awareness?
  • Which tactic is commonly used in vishing to reduce suspicion by the target?
  • What is the purpose of security awareness programs in relation to pretexting?
  • What risk is described when clicking malicious links in SPIM?
  • In whaling, which practice is commonly used to appear legitimate?
  • What type of content might be included in a phishing email to seem legitimate?
  • Beyond accessing accounts, what else can attackers do with phishing information?
  • What is elicitation in the context of social engineering?
  • What can links in phishing emails lead to?
  • What is the primary difference between whaling and regular spear phishing?
  • A successful whaling attack can lead to which outcome?
  • In a pretexting attack, what is the effect of thorough research on the success of the attack?
  • What are the risks associated with clicking links in malicious emails?
  • What action best helps defend against brand impersonation?
  • Which practice best reduces the risk of email-based attacks in an organization?
  • What type of information might a vishing automated system request?
  • What types of impersonation are common in whaling attacks?
  • Smishing is a type of phishing that uses which method?
  • What is the key to successful pretexting?
  • Why might whaling attacks attempt to reach executives by phone?
  • Which of the following best describes vishing?
  • What is the role of curiosity in phishing attacks?
  • How did a similar whaling attack affect Snapchat?
  • What is the likely goal of a provocative subject line in a phishing email?
  • Which of the following are commonly targeted by SPIM?
  • How does active listening help social engineers?
  • What is the significance of two-factor authentication (2FA) in relation to smishing?
  • What is pretexting in the context of social engineering?
  • How might an attacker use false statements to elicit information?
  • Describe the initial steps an attacker takes to launch an attack.
  • What techniques do social engineers use to elicit information?
  • Which outcome is a common goal of successful phishing attacks?
  • Credential harvesting commonly uses which tactic?
  • What is a phishing tactic that involves a fake software upgrade?
  • What is a common outcome for victims of lottery scams?
  • What is the significance of a single click by a user in cybersecurity?
  • Which feature is a common indicator that an email is a phishing attempt?
  • Why might salespeople use techniques similar to social engineers?
  • What does thorough pretexting research enable attackers to do?
  • Beacons in phishing emails reveal what information when the image is loaded?
  • What is a common tactic used by vishing attackers to create urgency?
  • What does the term spear phishing refer to?
  • How do advanced texting apps differ from the original SMS?
  • What is whaling in the context of email attacks?
  • What are the two types of vishing attempts?
  • What is the primary difference between phishing and smishing?
  • What is the goal of a vishing attack?
  • How can attackers impersonate a CEO in a spear phishing attack?
  • What outcome is associated with whaling against Seagate?
  • What is a potential impact of a successful cyberattack on an organization?
  • What should users be cautious about regarding emails that appear to be from legitimate companies?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy