1/19
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
John was eagerly waiting to buy a new Apple phone online that was out of stock. An attacker took advantage of this situation and sent a phishing email to the target users, encouraging them to click on a link provided in the email to buy the product. John clicked on the malicious link embedded in the email and was redirected to the website controlled by the attacker. As a result, John entered his bank account details on the attacker’s website.
Identify the social engineering context created by the attacker in the above scenario.
scarcity
Rocky, a professional hacker, targets an organization to perform a social engineering attack. He impersonated a legitimate employee of the company and requested the receptionist to send him important documents, as his files had been corrupted and he was required to send them immediately to the client.
Which of the following vulnerable behaviors was showcased by Rocky in the above scenario?
intimidation
Familarity
Familiarity or liking implies that people are more likely to be persuaded to do something when they are asked by someone whom they like. This indicates that people are more likely to buy products if they are advertised by an admired celebrity.
Greed
Some people are possessive by nature and seek to acquire vast amounts of wealth through illegal activities. Social engineers lure their targets to divulge information by promising something for nothing (appealing to their greed).
Intimidation
Intimidation refers to an attempt to intimidate a victim into taking several actions by using bullying tactics. It is usually performed by impersonating some other person and manipulating users into disclosing sensitive information.
Ross, a professional hacker, created a fake website and posted fake testimonials about a malicious anti-malware program that he developed. Upon reading the fake testimonials, some of the lured customers downloaded and installed the anti-malware.
Identify the behavior that made customers vulnerable to attack in the above scenario.
social proof
Social proof
Consensus or social proof refers to the fact that people are usually willing to like things or do things that other people like or do. Attackers take advantage of this by doing things like creating websites and posting fake testimonials from users about the benefits of certain products such as anti-malware (rogueware). Therefore, if users search the Internet to download the rogueware, they encounter these websites and believe the forged testimonials.
In which of the following phases of a social engineering attack do attackers try to reach out to disgruntled employees as they are easier to manipulate?
select a target
Don, a threat actor, targeted Bob, a new accountant at the target organization. Don started collecting all the sensitive information about the organization’s accounts, finance information, technologies in use, and upcoming plans and used this information to launch further attacks.
Identify the social engineering phase Don is currently executing in the above scenario.
exploit the relationship
In which of the following social engineering attacks do attackers install small cameras to record the victim’s system’s actions to obtain login details and other sensitive information?
shoulder surfing
In which of the following attacks does an attacker send an email or message to the target offering free gifts such as money and software, on the condition that the user forwards the email to a predetermined number of recipients?
chain letter
Rina, a student, was browsing online for information about her research project. She clicked on a link and suddenly observed many warning windows on her laptop about a virus she could not close. She became suspicious and reached out to her friend, who advised her to install reputed antivirus software.
Which of the following types of attack was performed on Rina in the above scenario?
hoax
In which of the following techniques does an attacker execute malicious programs on a victim’s computer or server, and when the victim enters any URL or domain name, it automatically redirects the victim’s traffic to the attacker-controlled website?
pharming
Spimming attack
A variant of spam that exploits Instant Messaging platforms to flood spam across the networks.
Jade, a professional hacker, was planning to enter the premises of an organization that allows access only to authorized persons. For this purpose, he creates a fake ID resembling the ID of the office staff and enters the restricted area by closely following an authorized person through a door that requires key access.
Identify the type of attack performed by Jade in the above scenario.
Tailgating
Abin, an attacker intending to access the critical assets and computing devices of an organization, impersonated Sally, a system administrator. Abin masquerades as Sally and gathers critical information from computing devices of the target organization.
Identify the type of insider threat demonstrated in the above scenario.
Compromised insider
Which of the following encompasses all forms of identity theft, where the perpetrators attempt to impersonate someone else simply to hide their original profile?
identity cloning
In which of the following types of identity theft does the perpetrator obtain information from different victims to create a new identity by stealing a social security number and use it with a combination of fake names, dates of birth, addresses, and other details required for creating a new identity?
synthetic identity theft
Which of the following is an anti-phishing tool that provides updated information about sites that users often visit and blocks harmful websites?
netcraft