Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium
A company is implementing a new security awareness training program. One module focuses on identifying emails that attempt to trick recipients into clicking malicious links or revealing sensitive information by impersonating a trusted entity. What type of attack is this module primarily designed to educate employees about?
- ARansomware attack
- BDenial-of-Service (DoS) attack
- CPhishing
- DMalware infection
Show answer & explanationAnswer & explanation
Correct answer: C. Phishing
The description of emails impersonating a trusted entity to trick recipients into clicking malicious links or revealing sensitive information is the classic definition of a phishing attack.
Why the other options are wrong
- A. Ransomware is a type of malware that encrypts data and demands payment, often delivered via phishing but distinct from the phishing technique itself.
- B. A DoS attack aims to make a service unavailable, not to trick users into revealing information via email.
- D. Malware infection is a broad term for malicious software, which phishing can lead to, but phishing itself is a method of delivery/social engineering.
Phishing
A social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (e.g., usernames, passwords, credit card details) or downloading malware by impersonating a trustworthy entity.
- Often delivered via email, SMS (smishing), or voice (vishing).
- Relies on deception and urgency.
- Aims to exploit human trust and curiosity.
Memory trick: Don't fall for the bait, verify the sender!