What is phishing?
- A.A method of breaking encryption
- B.A social engineering attack that uses deceptive messages to trick victims into revealing sensitive information
- C.A tool for scanning network vulnerabilities; spear phishing targets the largest possible audience with a generic message
- D.A type of denial-of-service attack, since brute force attacks succeed faster against longer and more complex passwords
Why B is correct
Phishing uses deceptive emails, messages, or websites that appear to be from trusted sources to trick victims into revealing sensitive information like passwords, credit card numbers, or installing malware. It is the most common initial attack vector in cybersecurity breaches.
Know someone studying for Security Fundamentals? Send them this one.