1/17
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What does phishing use to make spoofed electronic communications seem authentic?
Social engineering techniques
What actions might a phishing message try to convince a user to perform?
Installing malware disguised as an antivirus program or allowing a threat actor posing as a support technician to establish a remote access connection
How does a spoof website phishing attack capture login credentials?
The attacker emails users that their account must be updated or sends a disguised link to the spoofed site, and when users authenticate with the spoofed site, their login credentials are captured
What is spear-phishing?
A phishing attack where the attacker has some information that makes the target more likely to be fooled
What details might make a spear-phishing message seem genuine?
The name of a document the target is editing, the recipient's full name, job title, telephone number, or other details
What is whaling?
An attack directed specifically against upper levels of management in the organization
Why may upper management be more vulnerable to ordinary phishing attacks?
Their reluctance to learn basic security procedures
What is vishing?
Phishing conducted through a voice channel such as telephone or VoIP
Why can vishing be more effective than email phishing?
It can be much more difficult for someone to refuse a request made in a phone call compared to one made in an email
How has AI increased the effectiveness of vishing?
By allowing attackers to impersonate voices, increasing the chances of a user falling victim
What is smishing?
An attack performed through SMS text messages
What does a smishing message typically do?
Create a sense of urgency and encourage the target to click a link to a fake website or call a phone number to reveal login credentials and personal information
What is QR code phishing (Quishing)?
Using malicious QR codes to trick targets into visiting a fake website to enter credentials and reveal personal information
Why are QR codes useful to attackers in quishing?
They are essentially shortcuts to websites and downloads
What is an evil twin attack?
A rogue wireless access point used to try to harvest credentials
How can an evil twin imitate a legitimate network?
By using a similar network name (SSID) or using some denial of service technique to overcome the legitimate AP
How can an evil twin harvest authentication information?
By allowing devices to connect via open authentication and redirecting users' web browsers to a spoofed captive portal that prompts them for their network password
How is an evil twin similar to phishing?
It is similar to phishing but uses a rogue wireless access point instead of an email to try to harvest credentials