Worksheets2.8 Social Engineering 5
Total questions: 23
Worksheet time: 12mins
What is a characteristic of phishing?
It is easily identifiable as fraudulent.
It appears trustworthy.
It is only sent to a few selected individuals.
It is always blocked by email filters.
How do phishing attackers typically distribute their messages?
By sending personalized emails to each individual.
By posting on social media.
By sending mass emails.
By making phone calls.
Which of the following best describes the appearance of phishing emails?
They look suspicious and are easy to spot.
They contain a lot of spelling and grammar mistakes.
They look legitimate.
They are usually filtered into the spam folder.
What is the purpose of the email shown in the image?
To inform Tim Landon about a legitimate transaction
To request personal contact information under the guise of returning money
To confirm a scheduled meeting with Tim Landon
To provide customer service support for a PayPal transaction
What are the two key actions involved in Spear Phishing according to the learning material?
Send random emails, Use malware
Gather information, Send specific email
Hack into servers, Steal passwords
Create fake websites, Trick users
What is SMiShing commonly characterized by?
A) A legitimate text message asking for personal information
B) A text message with an urgent topic requiring immediate action and containing a malware link
C) A phone call from a trusted organization
D) An email with a secure attachment
What is a method used in pharming to redirect a user's traffic?
Installing antivirus software
DNS cache poisoning
Updating browser
Using a firewall
Which of the following is NOT a technique associated with pharming?
Execute malicious program
Host file modification
Phishing without a lure
Secure password management
What is the role of the DNS server in the phishing technique depicted in the image?
The DNS server correctly resolves the user's requested URL to the legitimate website.
The DNS server prevents the user from accessing any websites for security reasons.
The DNS server sends the user to a fake website instead of the legitimate one.
The DNS server encrypts the user's data to protect against phishing.
What is one of the risks associated with social networking mentioned in the learning material?
Improve security measures
Steal identities
Enhance privacy settings
Increase network speed
According to the learning material, what should individuals do in anticipation of attacks through social networking?
Ignore the threats
Delete social media accounts
Prepare for attacks
Share personal information
Which of the following is a type of phishing that targets specific individuals or companies?
Vishing
Whaling
Pharming
SMS phishing
What term is used to describe phishing attacks conducted through SMS messages?
Spear phishing
Vishing
SMS phishing
Pharming
What is the term for phishing attacks that are done via telephone or voice technology?
Spear phishing
Whaling
SMS phishing
Vishing
Which type of phishing involves the fraudulent practice of directing Internet users to a bogus website that mimics the appearance of a legitimate one?
Spear phishing
Vishing
SMS phishing
Pharming
What is social engineering?
A method of securing computer networks
The process of influencing people to obtain confidential information
A software development process
A technique for building social networks
What are the phases of a social engineering attack?
Planning, Attack, Retreat
Research, Hook, Play, Exit
Introduction, Growth, Maturity, Decline
Infection, Propagation, Execution, Maintenance
What is pretexting and how is it used in social engineering?
It is a way of encrypting messages to prevent social engineering
It is the use of a fabricated scenario to engage a targeted victim
It is a method of using social media to gather information
It is a legal technique used by law enforcement to catch cybercriminals
What are some of the most common social engineering techniques?
Phishing, Spear-phishing, Whaling, Vishing
Encryption, Decryption, Hashing, Salting
Debugging, Refactoring, Compiling, Testing
Firewalls, Antivirus, Intrusion Detection Systems, VPNs
How are attackers different in their motivations and approaches?
All attackers have the same motivation and approach
Attackers may be motivated by financial gain, revenge, or ideology and use different tactics
Attackers are only motivated by the challenge of breaking into systems
Attackers are different because they use different programming languages
How are motivation techniques effective in convincing targets to comply with a hacker's desires?
They are not effective; hackers rely solely on technical skills
They exploit human psychology to influence behavior and decision-making
They use legal persuasion to convince targets to comply
They involve offering financial rewards to targets for compliance
What are elicitation techniques and how are they effective for social engineering?
Methods to gather information through direct questions, effective because they are straightforward.
Techniques to subtly extract information without raising suspicion, effective because they are covert and non-threatening.
Strategies to protect information from being disclosed, effective because they prevent social engineering.
Tools used to encrypt data, effective because they make data unreadable to unauthorized users.
How do hackers use interview and interrogation techniques for social engineering?
By conducting formal interviews to offer jobs and extract information.
By using aggressive questioning to intimidate individuals into revealing information.
By pretending to conduct interviews or interrogations to elicit information in a seemingly legitimate context.
By providing training on interview skills to improve communication.
