Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A company is implementing a new security awareness training program. One module focuses on identifying emails that attempt to trick recipients into clicking malicious links or revealing sensitive information by impersonating a trusted entity. What type of attack is this module primarily designed to educate employees about?

  1. ARansomware attack
  2. BDenial-of-Service (DoS) attack
  3. CPhishing
  4. DMalware infection
Show answer & explanation

Correct answer: C. Phishing

The description of emails impersonating a trusted entity to trick recipients into clicking malicious links or revealing sensitive information is the classic definition of a phishing attack.

Why the other options are wrong

  • A. Ransomware is a type of malware that encrypts data and demands payment, often delivered via phishing but distinct from the phishing technique itself.
  • B. A DoS attack aims to make a service unavailable, not to trick users into revealing information via email.
  • D. Malware infection is a broad term for malicious software, which phishing can lead to, but phishing itself is a method of delivery/social engineering.

Phishing

A social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (e.g., usernames, passwords, credit card details) or downloading malware by impersonating a trustworthy entity.

  • Often delivered via email, SMS (smishing), or voice (vishing).
  • Relies on deception and urgency.
  • Aims to exploit human trust and curiosity.

Memory trick: Don't fall for the bait, verify the sender!

More Cybersecurity Fundamentals questions