Which social engineering attack vector uses spoofed emails, misleading hyperlinks, and look-alike landing pages to trick corporate employees into surrendering their login credentials? MCQ with Answer and Explanation
Which social engineering attack vector uses spoofed emails, misleading hyperlinks, and look-alike landing pages to trick corporate employees into surrendering their login credentials?
A. Phishing
B. DDoS Attack
C. SQL Injection
D. Man-in-the-Middle
Answer: Option A
Solution (By JKSSB Mock Tests)
Phishing involves masquerading as a trustworthy entity via digital communications to manipulate victims into revealing passwords, financial records, or sensitive personal tokens.
Explanation:
Cross-site scripting (XSS) is a common attack that injects malicious scripts into web applications, exploiting vulnerabilities to steal data or hijack sessions.
Explanation:
The principle of least privilege means providing users with only the access and permissions they need to perform their job functions, reducing the risk of misuse or unauthorized access.
What form of malware creates a secret communications link back to an attacker's control server, allowing them to remotely manipulate and spy on the victim's machine?
Explanation:
A RAT is a specialized Trojan variant that establishes an unauthorized administrative control channel, giving remote threat actors full command over infected endpoints.
No comments yet. Be the first to start the discussion!