5.6 Given a scenario, implement security awareness practices Flashcards
1
Q
Types of Phishing Attacks
A
■ Phishing
■ Vishing
■ Smishing
■ Spear Phishing
■ Whaling
■ Business Email Compromise
2
Q
Preventing Phishing Attacks
A
Anti-phishing Campaign
- Essential user security awareness training tool
- Should offer remedial training for users who fell victim to simulated phishing
emails
3
Q
key indicators that are associated with phishing attacks
A
- Urgency: to act immediately
- Unusual Requests: sensitive information, such as passwords or credit card numbers
- Mismatched URLs: you should
always hover your mouse over the link in the email for a few seconds and this will reveal the actual URL that the link is connected to
Strange Email Addresses: If the real email address and the displayed email address don’t match
Poor Spelling or Grammar
4
Q
Mitigation for Phishing attack
A
- Training
■ Report suspicious messages
Analyze the threat
■ Inform all users about the threat
If the phishing email was opened, conduct a quick investigation and triage
the user’s system
■ An organization should revise its security measures for every success phishing
attack