CIPA Social Engineering & Phishing Attacks 1 — Questions and Answers
Question 1: What is social engineering in the context of identity theft?
- Using malware to extract personal data from computers
- Manipulating people psychologically to divulge confidential information (Correct answer)
- Hacking into social media accounts using automated tools
- Stealing physical mail to obtain personal data
Correct answer: Manipulating people psychologically to divulge confidential information
Social engineering exploits human psychology rather than technical vulnerabilities, tricking victims into revealing sensitive information or performing actions that compromise their security.
Question 2: Which type of phishing attack is specifically targeted at a named individual or organization rather than sent broadly?
- Mass phishing
- Clone phishing
- Spear phishing (Correct answer)
- Vishing
Correct answer: Spear phishing
Spear phishing targets a specific individual or organization using personalized information to make the attack more convincing and harder to detect.
Question 3: What is 'vishing' as it relates to social engineering identity theft?
- A phishing attack conducted through video conferencing platforms
- A voice-based phishing attack conducted over telephone calls (Correct answer)
- A phishing attack using virtual reality environments
- A method of intercepting VoIP communications
Correct answer: A voice-based phishing attack conducted over telephone calls
Vishing (voice phishing) uses phone calls where attackers impersonate legitimate entities such as the IRS, banks, or tech support to steal personal information.
Question 4: Which red flag is MOST commonly associated with a phishing email?
- The email contains a company logo
- The email was sent during business hours
- The email creates urgency and requests immediate action on personal data (Correct answer)
- The email includes a physical mailing address
Correct answer: The email creates urgency and requests immediate action on personal data
Phishing emails typically create a false sense of urgency to pressure victims into acting quickly without verifying the request, such as 'Your account will be closed in 24 hours.'
Question 5: What is 'pretexting' in social engineering?
- Sending fraudulent text messages to steal information
- Creating a fabricated scenario to gain a victim's trust and extract information (Correct answer)
- Intercepting text communications between two parties
- Using pre-written scripts in phishing emails
Correct answer: Creating a fabricated scenario to gain a victim's trust and extract information
Pretexting involves creating a believable fabricated story or identity (e.g., posing as a bank auditor) to manipulate the victim into providing sensitive personal information.
Question 6: What is 'smishing' as used in identity theft attacks?
- Phishing attacks conducted through social media direct messages
- A technique for spoofing email sender addresses
- Phishing attacks conducted via SMS text messages (Correct answer)
- A method of stealing credentials through shared Wi-Fi
Correct answer: Phishing attacks conducted via SMS text messages
Smishing (SMS phishing) uses fraudulent text messages that often contain malicious links or prompt victims to call a number where attackers collect personal data.
Question 7: What is 'pharming' in the context of online identity threats?
- Mass-distributing phishing emails to thousands of recipients
- Harvesting personal data from agricultural industry databases
- Redirecting users from a legitimate website to a fraudulent one without their knowledge (Correct answer)
- Using automated bots to guess passwords on websites
Correct answer: Redirecting users from a legitimate website to a fraudulent one without their knowledge
Pharming redirects traffic from legitimate websites to malicious lookalike sites by corrupting DNS settings or hosts files, so victims unknowingly enter their credentials on a fake site.
What is social engineering in the context of identity theft?