A hacker sends a highly customized email targeting a specific university department head, using personal details gathered from research to steal institutional data. What tactic is this?, Smishing, Spear Phishing, Vishing, Broadcast Phishing, An email disguised as the University IT helpdesk demands an immediate password reset within 2 hours, threatening that the student's account will be permanently deleted if they delay. Which psychological triggers are being exploited?, Authority and Social Proof, Scarcity and Commitment, Urgency and Fear, Consensus and Liking, A threat actor assumes a fake identity (e.g., pretending to be an external financial auditor) and crafts a believable story to trick a finance officer into transferring funds. This combination of techniques is known as, Smishing and Spoofing, Business Email Compromise (BEC) and Pretexting, Spamming and Malicious Attachments, Logic Circuit Sniffing, Which technical control framework works together to verify an email's origin domain and uses cryptographic signatures to ensure the message wasn't altered in transit?, SPF (Sender Policy Framework) and DKIM, End-to-end VPN encryption, Two-Factor Authentication (2FA), Local Firewall Filters, You receive an unexpected email from a regular vendor containing a macro-enabled .xlsm file. What is the safest, most resilient behavioral action to take?, Download it and open it in a minimized browser window, Reply to the sender asking if they meant to send a virus, Ignore the warning and enable macros to view the content, Treat it as a potential malicious attachment and report it via official channels, A student receives an urgent SMS on their phone claiming to be from a courier service, stating a package cannot be delivered without clicking a tracking link. What specific type of phishing attack is this?, Smishing, Vishing, Spear Phishing, Pretexting, Why do social engineering attacks frequently succeed against organizations that have otherwise excellent, cutting-edge technical firewalls and security software?, Technical controls cannot scan incoming emails or attachments, Firewalls only work against internal physical threats, They bypass technical defences by directly targeting human psychology, Cryptographic signatures are easily guessed by automated AI tools, To effectively build community resilience and become a strong "last line of defence" against social engineering, individuals should be trained to, Recognise indicators of deception, resist psychological manipulation, and report suspicious communications, Manually configure the organization's SPF and DKIM protocols, Delete all incoming external emails without reading them, Re-program the university's technical spam filters

Social Engineering & Phishing

Leaderboard

Visual style

Options

Switch template

Continue editing: ?