CIPA Social Engineering & Phishing Attacks 2 — Questions and Answers
Question 1: What is 'baiting' in social engineering attacks?
- Sending enticing emails offering prizes to lure victims into clicking links
- Leaving infected physical media such as USB drives where targets will find and use them (Correct answer)
- Using attractive website designs to increase phishing click rates
- Posting fake job offers on social media to harvest resumes
Correct answer: Leaving infected physical media such as USB drives where targets will find and use them
Baiting involves leaving malware-laden physical media (like USB drives) in places where targets will find them; curiosity leads victims to plug the device in, compromising their system.
Question 2: What is a 'watering hole' attack?
- Sending phishing emails to employees near water coolers in offices
- Compromising a website frequently visited by a target group to infect their systems (Correct answer)
- Flooding a victim's inbox with fraudulent emails
- Intercepting data transmitted over public Wi-Fi hotspots
Correct answer: Compromising a website frequently visited by a target group to infect their systems
In a watering hole attack, criminals infect websites that their target audience regularly visits, exploiting the victims' trust in those familiar sites to deliver malware or steal credentials.
Question 3: What is 'whaling' in social engineering and phishing?
- Phishing attacks that cast a very wide net to catch as many victims as possible
- Targeted phishing attacks directed at high-level executives or decision-makers (Correct answer)
- Large-scale data breaches affecting thousands of users at once
- Social engineering attacks conducted through whale-watching forums
Correct answer: Targeted phishing attacks directed at high-level executives or decision-makers
Whaling targets high-value individuals such as CEOs, CFOs, or other executives whose credentials can enable large financial transfers or access to sensitive organizational data.
Question 4: What is 'clone phishing'?
- Creating fake duplicate social media profiles to steal identity data
- Replicating the victim's own past emails to trick them into responding
- Creating a near-identical copy of a legitimate email with malicious links replacing the originals (Correct answer)
- Copying entire websites and hosting them on lookalike domains
Correct answer: Creating a near-identical copy of a legitimate email with malicious links replacing the originals
Clone phishing takes a legitimate previously delivered email, duplicates it with malicious links or attachments substituted for the originals, then resends it appearing to come from a trusted sender.
Question 5: What psychological principle do social engineers MOST commonly exploit to gain compliance?
- Confirmation bias
- Authority and urgency (Correct answer)
- Cognitive dissonance
- The bystander effect
Correct answer: Authority and urgency
Social engineers exploit authority (claiming to be from the IRS, FBI, or a bank) combined with urgency (threatening immediate consequences) to pressure victims into bypassing their critical thinking.
Question 6: How does Business Email Compromise (BEC) typically leverage social engineering?
- By installing keyloggers on corporate email servers
- By impersonating executives or vendors via spoofed emails to authorize fraudulent wire transfers (Correct answer)
- By mass-phishing all employees with malware attachments
- By hacking into corporate email accounts using brute force
Correct answer: By impersonating executives or vendors via spoofed emails to authorize fraudulent wire transfers
BEC attackers impersonate a CEO, CFO, or trusted vendor using spoofed or compromised email accounts to convince employees to transfer funds or share sensitive credentials.
Question 7: What is the BEST immediate defense an organization should implement against social engineering attacks?
- Installing the latest antivirus software on all devices
- Using multi-factor authentication on all accounts
- Conducting regular employee security awareness training (Correct answer)
- Encrypting all email communications
Correct answer: Conducting regular employee security awareness training
Because social engineering targets human behavior rather than technology, regular security awareness training is the most effective defense, teaching employees to recognize and resist manipulation tactics.
What is 'baiting' in social engineering attacks?