Browse all practice questions for the Understanding Cyber Attacks: Phishing and Social Engineering Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

2026 Phishing and Social Engineering Practice Test – Complete Exam Preparation course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What personal information do scammers often attempt to obtain?
  • What type of information might a vishing automated system request?
  • What is the purpose of the malicious link in phishing emails?
  • What is vishing?
  • Which practice helps reduce risk from phishing attempts?
  • Why do most email programs not display images by default?
  • What is the role of curiosity in phishing attacks?
  • Which statement best describes spear phishing?
  • Whaling attackers commonly target which roles?
  • Digital signatures in email communications primarily help recipients verify what?
  • What is brand impersonation in the context of cyber attacks?
  • What should users do if they receive suspicious texts or emails?
  • What is the impact of social engineering techniques on cybersecurity?
  • What is the main goal of phishing emails?
  • How do attackers typically disguise malicious websites?
  • What is a common outcome for victims of lottery scams?
  • How do scammers typically use social media in their attacks?
  • What is the significance of the phrase 'We have noticed suspicious activity on your account' in phishing emails?
  • How might an attacker use a fake website in a brand impersonation scenario?
  • What is pretexting in the context of social engineering?
  • Which practice best reduces the risk of email-based attacks in an organization?
  • Which statement best describes how reflective questioning is used in social engineering?
  • What can links in phishing emails lead to?
  • Which scenario illustrates the common whaling tactic of impersonation?
  • What is the primary difference between phishing and smishing?
  • What is a drive-by download?
  • Which of the following is NOT listed as commonly targeted by SPIM?
  • What is the effect of attention during a conversation in social engineering?
  • Which line is commonly used in phishing emails to entice clicking a malicious link?
  • Which of the following is a common method criminals use to obtain email addresses for spam?
  • What is the purpose of the phishing email with the subject 'We have hijacked your baby'?
  • In a drive-by download phishing scheme, what typically happens when you visit the page?
  • What action best helps defend against brand impersonation?
  • Which of the following are examples of message-based attacks?
  • In whaling, which practice is commonly used to appear legitimate?
  • What distinguishes spear phishing from regular phishing?
  • Which of the following best describes whaling's target audience?
  • What is a key characteristic of phishing emails?
  • What are the risks associated with clicking links in malicious emails?
  • What is the classic Nigerian scam (419 scam)?
  • Brand impersonation often relies on which tactic?
  • What is reflective questioning?
  • What is a potential impact of a successful cyberattack on an organization?
  • What can happen if a user clicks on a malicious link in a spear phishing email?
  • Why might attackers purchase similar domain names?
  • What is the relationship between social engineering and cybersecurity awareness?
  • What is a recommended method for verifying the identity of someone requesting sensitive information?
  • Which statement about the impact of social engineering on cybersecurity is true?
  • What is a common security issue related to social media?
  • What is the purpose of a phishing email?
  • How can attackers exploit smishing?
  • Which statement about the impact of spam on productivity is true?
  • Which statement about drive-by downloads is true?
  • Which phrase is a common urgency tactic used in phishing emails?
  • What is bracketing in information elicitation?
  • Whaling attacks masquerade as complaints from which entities to gain executive attention?
  • What should you do if you receive a suspicious vishing call?
  • What is the significance of digital signatures in email security?
  • Why might salespeople use techniques similar to social engineers?
  • Which technique is used to harvest credentials?
  • Another COVID-19 scam targeted individuals seeking what for a fee?
  • What is a common tactic used in phishing emails to entice users to click a link?
  • Why are high-level executives referred to as 'whales' in whaling attacks?
  • What action should you take when you encounter a suspicious email about your account?
  • What is a phishing tactic that involves a fake software upgrade?
  • What role does trust play in brand impersonation attacks?
  • Give an example of a common pretexting scenario.
  • Which security feature helps verify the sender's identity in email messages?
  • Which organizations have experienced whaling attacks?
  • Which risk is commonly associated with social media impersonation through forged emails?
  • What is a common tactic used by attackers when purchasing a domain with a slight misspelling of a legitimate site?
  • What types of individuals might an attacker impersonate in a pretexting attack?
  • What is the significance of two-factor authentication (2FA) in relation to smishing?
  • What common strategy do vishing attackers use to appear legitimate?
  • Describe the initial steps an attacker takes to launch an attack.
  • What is a potential consequence of opting out of a mailing list?
  • One COVID-19 related scam involved a message that claimed you had contact with someone who tested positive and included what?
  • Which outcome is not typically listed as a potential impact of a cyberattack?
  • Which of the following is a prudent step when you suspect a text or email is fraudulent?
  • Which statement best describes spear phishing?
  • What are the two types of vishing attempts?
  • Beyond accessing accounts, what else can attackers do with phishing information?
  • Which organization might whaling impersonate to gain executive attention?
  • Which organizations have experienced whaling attacks?
  • What do victims of the Nigerian scam often end up doing?
  • Which of the following is not a tactic used by criminals in phishing attacks?
  • What is the primary goal of brand impersonation?
  • Which of the following best describes vishing?
  • Which scenario best illustrates elicitation in social engineering?
  • What is typical content of a phishing email designed to install malware?
  • What is a potential consequence of a successful whaling attack?
  • What is spear phishing?
  • What is one solution to deter spear phishing attacks?
  • What personal information might vishing attackers try to obtain?
  • How does vishing typically use VoIP technology?
  • What is whaling in cybersecurity?
  • Which outcome is a common goal of successful phishing attacks?
  • What is the primary difference between whaling and regular spear phishing?
  • How do attackers use compromised servers in their attacks?
  • How do attackers benefit from obtaining personal information through vishing?
  • What outcome is associated with whaling against Seagate?
  • How do advanced texting apps differ from the original SMS?
  • What should you remember about spam and phishing?
  • What is the main difference between spam and phishing?
  • What should users be cautious about regarding emails that appear to be from legitimate companies?
  • Which statement best describes pretexting?
  • What is the relationship between botnets and phishing emails?
  • Which statement about smishing is true?
  • Which of the following is a classic example of a phishing attack?
  • What is the effect of attackers' full attention during a conversation in social engineering?
  • What is a botnet in the context of phishing?
  • What might attackers do with information gathered through elicitation?
  • What happens when a user clicks a malicious link in a phishing email?
  • How can you identify the actual sender of an email that appears to be from a friend?
  • What are message-based attacks?
  • What is the significance of a single click by a user in cybersecurity?
  • Which tactic is commonly used in vishing to reduce suspicion by the target?
  • Credential harvesting often involves which practice?
  • Which statement describes the role of digital signatures in email security?
  • Which of the following is NOT a characteristic of elicitation in social engineering?
  • Credential harvesting commonly uses which tactic?
  • What is a common example of a brand impersonation attack?
  • Vishing uses which channel?
  • What is phishing?
  • SPIM is characterized by real-time communication delivered via which channel?
  • Drive-by malware is primarily enabled by which action?
  • What role does social engineering play in cyberattacks?
  • What is a common distraction used in phishing emails during a drive-by download?
  • Which set describes message-based attacks?
  • What should employees be educated about to minimize the risks of email attacks?
  • What is a common tactic used by criminals in phishing attacks?
  • What might be a consequence of brand impersonation for victims?
  • Which strategy helps reduce brand impersonation risk?
  • Beacons in phishing emails reveal what information when the image is loaded?
  • What is the key to successful pretexting?
  • What best describes SPIM?
  • Why do spam emails often include opt-out instructions?
  • Give an example of a smishing attack.
  • What is a common consequence of brand impersonation phishing emails?
  • Why is user education important in preventing cyberattacks?
  • How might an attacker use false statements to elicit information?
  • Vishing is a phishing attack conducted over the
  • In a pretexting attack, what is the effect of thorough research on the success of the attack?
  • Which statement about brand impersonation and trust is true?
  • Why do attackers purchase similar domain names?
  • What risk is described when clicking malicious links in SPIM?
  • What is spam in the context of email?
  • What best describes spear phishing?
  • A successful whaling attack can lead to which outcome?
  • What is a common tactic used by vishing attackers involving credit cards?
  • What does the term spear phishing refer to?
  • What does thorough pretexting research enable attackers to do?
  • Which feature is a common indicator that an email is a phishing attempt?
  • Which technology is used to spoof caller ID in vishing?
  • How can attackers impersonate a CEO in a spear phishing attack?
  • Which statement about whaling is true?
  • What is the main method attackers use to send spear phishing emails?
  • How can SPIM bypass typical security measures?
  • What is whaling in the context of email attacks?
  • What should you be wary of when you receive emails related to social media interactions?
  • What types of impersonation are common in whaling attacks?
  • Which of the following are commonly targeted by SPIM?
  • In phishing campaigns, attackers often prompt users to take what action that leads to malware installation?
  • Which of the following illustrates a common pretexting scenario?
  • Which tactic would attackers use to make a malicious website appear legitimate?
  • What is the impact of spam on productivity?
  • What was a notable whaling attack involving Seagate?
  • How do beacons work in phishing emails?
  • If you receive a suspicious email about your account, what is the safest course of action?
  • How can brand impersonation exploit consumer trust?
  • Which statement best describes smishing?
  • What is a common response from vishing attackers when asked to stop calling?
  • What is a common tactic used by vishing attackers to create urgency?
  • How did a similar whaling attack affect Snapchat?
  • What is the role of digital signatures in combating spear phishing?
  • What is the goal of a vishing attack?
  • Smishing is phishing conducted via
  • When verifying identity for sensitive information requests, which practice is recommended?
  • What techniques do social engineers use to elicit information?
  • Smishing is a type of phishing that uses which method?
  • How do attackers typically request money in phishing scams?
  • What is vishing?
  • Which of the following best describes a hallmark of spear phishing?
  • Why might a phishing email include an attachment that looks like a photo?
  • What type of information could attackers potentially gather after phishing?
  • Which statement defines a drive-by download?
  • What is a drive-by malware attack?
  • What type of content might be included in a phishing email to seem legitimate?
  • What measures can organizations take to defend against pretexting attacks?
  • What is the potential risk if a user responds to a smishing text?
  • What is the purpose of using a malicious link in an email?
  • Why might whaling attacks attempt to reach executives by phone?
  • Drive-by download description?
  • What is the likely goal of a provocative subject line in a phishing email?
  • Which of the following is required by law for companies sending marketing emails?
  • What is a recommended safe practice to reduce phishing risk?
  • Which of the following best describes what attackers can do with information obtained from a successful phishing attack?
  • What is phishing?
  • What is the typical goal when a phishing email includes a malicious link?
  • How does active listening help social engineers?
  • What is the purpose of security awareness programs in relation to pretexting?
  • If you receive an email claiming to be from a famous company asking you to revalidate credentials via a link, what should you do?
  • What is elicitation in the context of social engineering?
  • What is smishing?
  • What is a recommended defense against brand impersonation attacks?
  • What can the information obtained from phishing enable attackers to do?
  • What is the primary goal of vishing?
  • Which statement best helps prevent phishing-like attacks?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy