Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A company is implementing a new security awareness training program. One module focuses on teaching employees to identify and report suspicious emails that attempt to trick them into revealing sensitive information, such as login credentials or financial details. Which common security threat is this training module primarily addressing?
- APhishing
- BBrute-force attacks
- CMalware infection
- DInsider threats
Show answer & explanationAnswer & explanation
Correct answer: A. Phishing
The scenario describes an attempt to trick employees via email into revealing sensitive information, which is the definition of a phishing attack. Security awareness training is a key defense against such social engineering techniques.
Why the other options are wrong
- B. Brute-force attacks involve systematically trying many passwords, not tricking users via email.
- C. While phishing can lead to malware infection, the primary action described (tricking users into revealing info) is phishing itself.
- D. Insider threats originate from within the organization, whereas phishing is typically an external attack, though an insider could be a target.
Phishing
A type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information, such as usernames, passwords, and credit card details, often by disguising themselves as a trustworthy entity in electronic communication.
- Often uses email, text messages (smishing), or phone calls (vishing).
- Relies on deception and urgency to manipulate victims.
- Aims to steal credentials, financial information, or install malware.
Memory trick: Social engineering: Phishing is bait, pretexting is a story, tailgating is following.