Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard
A security team is implementing a new security awareness program for all employees. A key component of the program is to educate users on how to identify and report suspicious emails that attempt to trick them into revealing sensitive information or clicking malicious links. Which specific threat does this part of the training aim to mitigate?
- ASQL injection
- BPhishing
- CRansomware
- DBrute-force attacks
Show answer & explanationAnswer & explanation
Correct answer: B. Phishing
Phishing is a social engineering attack that uses deceptive emails or messages to trick recipients into revealing sensitive information or performing actions that compromise security. Training employees to identify and report such emails is a direct mitigation strategy against phishing.
Why the other options are wrong
- A. SQL injection targets database vulnerabilities through web application input, unrelated to email-based social engineering.
- C. Ransomware encrypts data and demands payment, often delivered via phishing but the training directly targets the delivery mechanism (phishing) rather than the payload itself.
- D. Brute-force attacks involve trying many passwords, not email deception.
Phishing Attack
A type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (e.g., usernames, passwords, credit card details) or clicking malicious links, often via deceptive emails or messages.
- Relies on deception and urgency.
- Often mimics legitimate entities.
- A common vector for malware delivery and credential theft.
Memory trick: Phishing is like 'fishing' for your info with a tricky bait email.