Question 1
How do attackers typically request money in phishing scams?
Correct Answer:
They often ask for small fees or bank information with the promise of a larger payout
Explanation:
Phishers often monetize scams by playing on greed and urgency: they imply you’re about to receive a large payout but require you to pay a small upfront fee or reveal bank information to unlock it. This upfront request lowers skepticism and can lead you to share sensitive financial details or transfer money, enabling the attacker to profit. That pattern—asking for small fees or banking data with the promise of a bigger reward—is why this option is the best fit for how attackers typically request money in phishing scams. Be wary of messages that push for quick payments or financial details in the name of a supposedly huge payout.
Question 2
Why might salespeople use techniques similar to social engineers?
Correct Answer:
To develop rapport and gather information that can help close a sale.
Explanation:
In sales, the point of using social-skills tactics is to build trust and understand the customer’s needs so you can tailor a solution and move toward a purchase. Developing rapport helps the customer feel comfortable, while asking thoughtful questions reveals requirements, budget, decision timelines, and potential objections. That information lets the salesperson present the right value, address concerns, and increase the likelihood of closing the deal. This aligns with ethical, professional practice: the goal is to help the customer while guiding them to a fit, not to mislead or pressure them into unsafe actions. Deception, causing harm, or flouting laws would be counterproductive and illegal, so they don’t fit as legitimate sales approaches. In security-minded thinking, it’s useful to recognize that techniques resembling social engineering can be legitimate when used transparently to assess needs and provide appropriate solutions, always with consent and compliance in mind.
Question 3
Which organization might whaling impersonate to gain executive attention?
Correct Answer:
Both Better Business Bureau and Justice Department
Explanation:
Whaling relies on using authority and urgency to trigger quick, impulsive actions from busy executives. Attackers pretend to be trusted organizations so the recipient accepts the message at face value without scrutinizing it. The Better Business Bureau is a well-known watchdog that signals legitimacy in business matters, while the Justice Department carries real enforcement power and can create fear of legal consequences. Messages claiming to come from either of these organizations push executives to act—such as approving transfers, sharing sensitive data, or initiating compliance steps—before verifying the request. Since attackers often blend multiple credible sources to boost credibility, choosing the option that includes both BBB and Justice Department best reflects how whaling operates, making it the strongest answer.
Question 4
Credential harvesting often involves which practice?
Correct Answer:
Using social engineering to coax users into entering usernames and passwords on bogus sites.
Explanation:
Credential harvesting hinges on social engineering—tricking people into revealing their credentials by presenting fake login pages or convincing messages that persuade them to enter usernames and passwords. Attackers rely on the human element, crafting interfaces that look legitimate so users believe they’re signing into a real site and, unknowingly, hand over their access details. Once captured, those credentials can be reused to access accounts or compromise other services where people reuse passwords. Directly stealing passwords from a secure server without user input is about breaching a system’s data store, not about coaxing users to reveal credentials themselves. Hardware keyloggers focus on recording keystrokes on a device, which is a different technique that doesn’t rely on convincing the user to enter credentials on a bogus site. Intercepting data over public Wi-Fi involves network eavesdropping, which may capture credentials but again targets the transmission rather than obtaining them through deceptive login interfaces.
Question 5
Which organizations have experienced whaling attacks?
Correct Answer:
Seagate and Snapchat
Explanation:
Whaling is targeted phishing aimed at high‑level executives. The attacker researches the organization and crafts a convincing message that appears to come from a trusted colleague, often involving urgent financial or legal matters. The goal is to deceive the recipient into transferring funds, revealing credentials, or sharing sensitive information. The best answer points to organizations that have publicly faced such executive-targeted phishing. Seagate and Snapchat have been cited in discussions of whaling campaigns where messages were tailored to senior staff to persuade them to take risky actions, such as authorizing payments or divulging access details. This illustrates how attackers go after authority figures within an organization, exploiting urgency and legitimacy to bypass normal controls. It’s a reminder that effective defense combines user education, verification steps for financial requests, and strong authentication for privileged accounts.
Question 1
Exam overview

About this Exam

Prepare with the Understanding Cyber Attacks Phishing and Social Engineering Practice Test practice quiz. This question bank includes 10 questions covering attacks, attackers, whaling, smishing, and understanding. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Understanding Cyber Attacks Phishing and Social Engineering Practice Test

This practice set contains 10 questions from the matching question bank and focuses on attacks, attackers, whaling, smishing, and understanding. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions