All questions

Understanding Cyber Attacks: Phishing and Social Engineering Practice Test

Browse all practice questions for the Understanding Cyber Attacks: Phishing and Social Engineering Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Master Cyber Defense 2026: Catch the Phish and Outsmart Social Engineers! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Beyond accessing accounts, what else can attackers do with phishing information?
  • How do attackers typically request money in phishing scams?
  • Which of the following is required by law for companies sending marketing emails?
  • What is a potential impact of a successful cyberattack on an organization?
  • What happens when a user clicks a malicious link in a phishing email?
  • Which tactic would attackers use to make a malicious website appear legitimate?
  • Beacons in phishing emails reveal what information when the image is loaded?
  • One COVID-19 related scam involved a message that claimed you had contact with someone who tested positive and included what?
  • What should you remember about spam and phishing?
  • In whaling, which practice is commonly used to appear legitimate?
  • How does vishing typically use VoIP technology?
  • Why might attackers purchase similar domain names?
  • What is reflective questioning?
  • What is a common consequence of brand impersonation phishing emails?
  • Which of the following is a classic example of a phishing attack?
  • How can SPIM bypass typical security measures?
  • Which statement describes the role of digital signatures in email security?
  • What is a potential consequence of opting out of a mailing list?
  • Which action helps verify the true origin of an email that claims to be from a friend?
  • How did a similar whaling attack affect Snapchat?
  • What is a drive-by download?
  • What can the information obtained from phishing enable attackers to do?
  • What types of individuals might an attacker impersonate in a pretexting attack?
  • Which scenario best illustrates elicitation in social engineering?
  • Which strategy helps reduce brand impersonation risk?
  • What is a key characteristic of phishing emails?
  • What is the purpose of the phishing email with the subject 'We have hijacked your baby'?
  • What is the primary goal of vishing?
  • Which statement about the impact of social engineering on cybersecurity is true?
  • Which of the following is NOT listed as commonly targeted by SPIM?
  • Which practice helps reduce risk from phishing attempts?
  • Which organizations have experienced whaling attacks?
  • Why is user education important in preventing cyberattacks?
  • What is smishing?
  • What is the classic Nigerian scam (419 scam)?
  • Whaling attackers commonly target which roles?
  • What can links in phishing emails lead to?
  • Which statement about drive-by downloads is true?
  • What is a common tactic used by vishing attackers to create urgency?
  • What is the effect of attackers' full attention during a conversation in social engineering?
  • Give an example of a common pretexting scenario.
  • Which organizations have experienced whaling attacks?
  • What should you be wary of when you receive emails related to social media interactions?
  • Which scenario illustrates the common whaling tactic of impersonation?
  • What is vishing?
  • What role does social engineering play in cyberattacks?
  • What distinguishes spear phishing from regular phishing?
  • What role does trust play in brand impersonation attacks?
  • What type of information could attackers potentially gather after phishing?
  • What does the term spear phishing refer to?
  • Digital signatures in email communications primarily help recipients verify what?
  • What is the relationship between social engineering and cybersecurity awareness?
  • A successful whaling attack can lead to which outcome?
  • Which outcome is a common goal of successful phishing attacks?
  • What might be a consequence of brand impersonation for victims?
  • What is a recommended defense against brand impersonation attacks?
  • What is a common tactic used by criminals in phishing attacks?
  • Which of the following best describes what attackers can do with information obtained from a successful phishing attack?
  • What should employees be educated about to minimize the risks of email attacks?
  • Describe the initial steps an attacker takes to launch an attack.
  • What risk is described when clicking malicious links in SPIM?
  • Vishing is a phishing attack conducted over the
  • What is vishing?
  • What is a common tactic used by vishing attackers involving credit cards?
  • What is the purpose of the malicious link in phishing emails?
  • What is a common tactic used in phishing emails to entice users to click a link?
  • Which statement best describes how reflective questioning is used in social engineering?
  • Why are high-level executives referred to as 'whales' in whaling attacks?
  • What is a common response from vishing attackers when asked to stop calling?
  • In a pretexting attack, what is the effect of thorough research on the success of the attack?
  • Smishing is a type of phishing that uses which method?
  • Which statement best describes spear phishing?
  • What is the main method attackers use to send spear phishing emails?
  • What are the risks associated with clicking links in malicious emails?
  • How can you identify the actual sender of an email that appears to be from a friend?
  • Which of the following are commonly targeted by SPIM?
  • What outcome is associated with whaling against Seagate?
  • What is the purpose of a phishing email?
  • Smishing is phishing conducted via
  • What is the effect of attention during a conversation in social engineering?
  • What is spam in the context of email?
  • What is a common security issue related to social media?
  • What is the role of curiosity in phishing attacks?
  • What is the primary difference between phishing and smishing?
  • Which organization might whaling impersonate to gain executive attention?
  • What personal information do scammers often attempt to obtain?
  • Why do spam emails often include opt-out instructions?
  • Which technology is used to spoof caller ID in vishing?
  • What types of impersonation are common in whaling attacks?
  • Which tactic is commonly used in vishing to reduce suspicion by the target?
  • Which of the following are examples of message-based attacks?
  • What is pretexting in the context of social engineering?
  • What personal information might vishing attackers try to obtain?
  • What is the purpose of security awareness programs in relation to pretexting?
  • What is the key to successful pretexting?
  • Vishing uses which channel?
  • What should users do if they receive suspicious texts or emails?
  • Which set describes message-based attacks?
  • Which of the following best describes a hallmark of spear phishing?
  • Credential harvesting often involves which practice?
  • What is a common example of a brand impersonation attack?
  • Which statement defines a drive-by download?
  • Which feature is a common indicator that an email is a phishing attempt?
  • What is the impact of social engineering techniques on cybersecurity?
  • How can brand impersonation exploit consumer trust?
  • Drive-by malware is primarily enabled by which action?
  • What is a potential consequence of a successful whaling attack?
  • Which statement about brand impersonation and trust is true?
  • Drive-by download description?
  • Why might a phishing email include an attachment that looks like a photo?
  • Which statement about smishing is true?
  • In a drive-by download phishing scheme, what typically happens when you visit the page?
  • Which risk is commonly associated with social media impersonation through forged emails?
  • What is the likely goal of a provocative subject line in a phishing email?
  • Which statement best describes spear phishing?
  • What is the main difference between spam and phishing?
  • What is whaling in cybersecurity?
  • How can attackers impersonate a CEO in a spear phishing attack?
  • What are the two types of vishing attempts?
  • What is brand impersonation in the context of cyber attacks?
  • If you receive an email claiming to be from a famous company asking you to revalidate credentials via a link, what should you do?
  • What can happen if a user clicks on a malicious link in a spear phishing email?
  • SPIM is characterized by real-time communication delivered via which channel?
  • Which outcome is not typically listed as a potential impact of a cyberattack?
  • What is the main goal of phishing emails?
  • Why might whaling attacks attempt to reach executives by phone?
  • What should users be cautious about regarding emails that appear to be from legitimate companies?
  • What is the primary goal of brand impersonation?
  • What is phishing?
  • Why do most email programs not display images by default?
  • What best describes spear phishing?
  • What measures can organizations take to defend against pretexting attacks?
  • Give an example of a smishing attack.
  • Which of the following best describes whaling's target audience?
  • Which statement about the impact of spam on productivity is true?
  • What is bracketing in information elicitation?
  • Brand impersonation often relies on which tactic?
  • How does active listening help social engineers?
  • What is the significance of digital signatures in email security?
  • Which of the following is not a tactic used by criminals in phishing attacks?
  • Whaling attacks masquerade as complaints from which entities to gain executive attention?
  • Which statement best helps prevent phishing-like attacks?
  • Which of the following best describes vishing?
  • Which technique is used to harvest credentials?
  • What is the significance of a single click by a user in cybersecurity?
  • How do advanced texting apps differ from the original SMS?
  • What is the significance of the phrase 'We have noticed suspicious activity on your account' in phishing emails?
  • What is a recommended safe practice to reduce phishing risk?
  • What is typical content of a phishing email designed to install malware?
  • What is whaling in the context of email attacks?
  • Why might salespeople use techniques similar to social engineers?
  • How do scammers typically use social media in their attacks?
  • Another COVID-19 scam targeted individuals seeking what for a fee?
  • What is a common distraction used in phishing emails during a drive-by download?
  • How do attackers typically disguise malicious websites?
  • Which security feature helps verify the sender's identity in email messages?
  • What type of information might a vishing automated system request?
  • Which statement best describes smishing?
  • What action best helps defend against brand impersonation?
  • What is a botnet in the context of phishing?
  • What does thorough pretexting research enable attackers to do?
  • Why do attackers purchase similar domain names?
  • What is the purpose of using a malicious link in an email?
  • What is the relationship between botnets and phishing emails?
  • What is one solution to deter spear phishing attacks?
  • Which statement about whaling is true?
  • What best describes SPIM?
  • How do attackers benefit from obtaining personal information through vishing?
  • When verifying identity for sensitive information requests, which practice is recommended?
  • What is a common outcome for victims of lottery scams?
  • What common strategy do vishing attackers use to appear legitimate?
  • If you receive a suspicious email about your account, what is the safest course of action?
  • What are message-based attacks?
  • What is a recommended method for verifying the identity of someone requesting sensitive information?
  • What is a common tactic used by attackers when purchasing a domain with a slight misspelling of a legitimate site?
  • What is the impact of spam on productivity?
  • What might attackers do with information gathered through elicitation?
  • What is the significance of two-factor authentication (2FA) in relation to smishing?
  • In phishing campaigns, attackers often prompt users to take what action that leads to malware installation?
  • What is the potential risk if a user responds to a smishing text?
  • What is elicitation in the context of social engineering?
  • How do beacons work in phishing emails?
  • Which phrase is a common urgency tactic used in phishing emails?
  • How might an attacker use a fake website in a brand impersonation scenario?
  • What action should you take when you encounter a suspicious email about your account?
  • Which practice best reduces the risk of email-based attacks in an organization?
  • How can attackers exploit smishing?
  • Which line is commonly used in phishing emails to entice clicking a malicious link?
  • Which of the following is a prudent step when you suspect a text or email is fraudulent?
  • How might an attacker use false statements to elicit information?
  • What was a notable whaling attack involving Seagate?
  • What is a drive-by download?
  • Which of the following is NOT a characteristic of elicitation in social engineering?
  • What is the goal of a vishing attack?
  • What type of content might be included in a phishing email to seem legitimate?
  • What should you do if you receive a suspicious vishing call?
  • Which of the following is a common method criminals use to obtain email addresses for spam?
  • Which statement best describes pretexting?
  • What is the typical goal when a phishing email includes a malicious link?
  • What is a phishing tactic that involves a fake software upgrade?
  • What is a drive-by malware attack?
  • What is spear phishing?
  • What is phishing?
  • Credential harvesting commonly uses which tactic?
  • How do attackers use compromised servers in their attacks?
  • What do victims of the Nigerian scam often end up doing?
  • What techniques do social engineers use to elicit information?
  • What is the primary difference between whaling and regular spear phishing?
  • Which of the following illustrates a common pretexting scenario?
  • What is the role of digital signatures in combating spear phishing?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy