WorksheetsSocial Engineering & Access Control Quiz
Total questions: 25
Worksheet time: 13mins
How can users defend against watering hole attacks?
By installing anti-virus and anti-malware programs.
By avoiding common websites frequented by many users.
By relying on browser extensions to detect malicious URLs.
Which of the following best describes phishing?
Fishing for compliments on social media
Attempting to gain sensitive information through electronic communication by posing as a trustworthy source
Using real fishing as a metaphor for online security
Sending out random emails without a specific target
What is a common characteristic of obvious phishing attempts?
Proper grammar and spelling
Well-designed graphics and fonts
Misspelled words and odd graphics
Promises that seem too good to be true
What is another term for phishing done by phone call or voice message?
Voice Broadcasting
Voice Messaging
Vishing
Audio Phishing
What is whaling in the context of phishing?
Phishing attempt directed at high-profile targets like CEOs
Phishing attempt directed at low-profile individuals
Phishing attempt using cloned email addresses
Phishing attempt through voice messages
What is social engineering?
A form of psychological manipulation to gain access to sensitive information or perform unauthorized actions
A technique used by hackers to exploit software vulnerabilities
A physical intrusion into a secure facility
A marketing strategy to promote products on social media
How can individuals defend against social engineering attacks?
By complying with all requests received via email
By ignoring any communication from unknown sources
By sharing personal information freely
By using the same password for all accounts
SPAM emails can be identified by:
Their personalized content
Their encrypted attachments
Their generic and unsolicited nature
Their secure links
Which group of threat actors is fueled by money and the desire to gain power to continue their influence?
Hacktivists
Shadow IT
Nation States and APT
Competition
What do Insider Threats primarily exploit to cause damage within an organization?
Exploits and attacks for a cause
Advanced government or military organizations
Shadow IT infrastructure
Weak points known within the organization
Which type of hackers intend to cause damage and harm to their targets?
White hat hackers
Grey hat hackers
Black hat hackers
Ethical hackers
Shadow IT operates:
As part of larger organizations, following IT department rules strictly
Within larger organizations but not following IT department rules
Independently, without any connection to larger organizations
Solely for financial gain without regard to organizational rules
What principle of the CIA Triad ensures that authorized users have timely and reliable access to information and systems when needed?
Confidentiality
Integrity
Availability
Authorization
What is the purpose of the CIA Triad in information security?
To authenticate users accessing the system
To provide a framework for developing and implementing security controls
To enforce access control policies
To monitor network traffic and detect anomalies
What is Phishing?
Web pages you have visited that are stored on your hard drive
Text files some websites use to identify users
A scam to get confidential information
A form where you type confidential information
What is the best definition of Spear Phishing?
"A Phishing email aimed directly at you"
"A malicious virus that can encrypt or lock your computer"
"A method hackers can use to guess your password"
"A random Phishing email sent to a massive group"
Which of these is the best definition of Shoulder Surfing?
Calling someone to create an invented situation that increases the chance they will share sensitive information with you.
Sending an email that pretends to be from a reputable company which usually has a link to click that takes you to a website that looks real but is not.
A cyber attack that redirects a user from a real URL to a website that looks real but is not.
Looking at someone entering their personal data into a system and copying what you see.
Which of the following is a common sign of a phishing email?
Personalized greeting with your full name
Professional language and formatting
Urgent request for sensitive information
Emails from known contacts only
Which of the following is a method to prevent unauthorized access to a network?
Allowing guest access to all network resources
Using strong passwords and two-factor authentication
Sharing passwords with trusted colleagues
Disabling firewalls for easier access
What is a watering hole attack?
A type of attack where hackers target a specific website frequented by a particular group
A technique used to exploit software vulnerabilities in outdated systems
An attack that involves sending phishing emails to random users
A method of social engineering that involves impersonating a trusted source
Which of the following is a common defense against watering hole attacks?
Visiting only untrusted websites
Regularly updating and patching software
Disabling all browser extensions
Using the same password across multiple sites
How do attackers typically choose their targets in a watering hole attack?
By identifying websites frequently visited by a specific group or organization
By focusing on websites with strong security measures
By selecting random websites with high traffic
By targeting websites with outdated content
How can users protect themselves from typosquatting attacks?
By disabling browser security features
By carefully checking the URL before entering sensitive information
By using a single password for all accounts
By frequently changing their email address
Which of the following is a common sign of a typosquatting website?
Secure HTTPS connection
URL with minor spelling errors or extra characters
High-quality content and design
Official contact information
How can organizations promote continuous learning in security practices?
Ignore security threats
Discourage employees from reporting suspicious behavior
Hold regular interactive training sessions
Limit access to security resources
