Explore

Recognizing Phishing Attacks

by turhan-ergene

Phishing is the most common way attackers get into accounts and networks, and it works by exploiting trust and urgency rather than technical flaws. This room covers how to recognize phishing attempts across email, text and impersonated accounts, and what to do instead of clicking.

You're previewing this room. Log in or create a free account to answer the questions and track your progress.
Study material

Phishing attacks work by impersonating someone the target trusts, such as a bank, a coworker, or a delivery company, and by creating pressure to act immediately, before the target has time to check whether the message is real. The request itself is usually ordinary, a click, a reply, or a login, and the urgency is what does the work: a calm reader has time to notice something is wrong.

An email appears to come from your company's IT department, warning that your account will be locked in ten minutes unless you click a link and re-enter your password. Based on the passage above, what is the strongest reason to be suspicious of it before you even open the link?

multiple choice

AIT departments never contact staff about accounts by email
BThe message greets you by your first name
CIt creates urgency so you have no time to verify it
DThe countdown given is precisely ten minutes long
Think about why the passage says urgency is useful to an attacker.
Log in to answer

Ready to test yourself?

Sign up free to answer, score points, and build your streak.