Drill #4 Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

Phishing is…

A

Phishing is…
masquerading as a trustworthy entity using social engineering to acquire sensitive information through emails, voice, and text messaging

Phishing is the major tool used by the bad guys to get users to click on something and lead them to confidential information, like usernames, passwords, social security numbers, names, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

spear phishing

A

A small, focused, targeted phishing attack on a specific person or organization, with the goal to penetrate their defenses. Personalized for the individual.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

phishing attack surface

A

The quantity of emails exposed on the internet. The more email addresses exposed, the bigger the attack footprint is and the higher the risk for phishing attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Phish-prone Percentage

A

A term coined by KnowBe4 that indicates the percentage of employees that are prone to click on phishing links.

The customer starts with a baseline (a starting point used for comparison) percentage, which is the percentage of users who click on phishing links before being trained. Once trained, the test is done again 12 months later, to see the improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

social engineering

A

The act of manipulating people into performing actions or divulging sensitive information.

The term typically applies to trickery or deception for the purpose of information gathering, fraud, or computer system access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CEO fraud

A

A spear phishing attack that targets high-risk users—people in Accounting, HR, or executive assistants—in which the hacker claims to be the CEO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

vishing

A

A phishing attack conducted by telephone. Vishing is the phone equivalent of a phishing attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

smishing

A

Phishing conducted via Short Message Service (SMS), a telephone-based text messaging service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

email spoofing

A

phishing attack where the sender’s email address is faked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly