1 | Page
Barracuda internship Questions and Correct
Answers
13 threats type Ans: spam, malware, data exfiltration, URL
phishing, scamming, spear phishing, domain impersonation, brand
impersonation, extortion, business email compromise,
conversational highjacking, lateral phishing, account takeover
Spam Ans: unsolicited, unwanted commercial email messages
also known as junk email
-lowers productivity by flooding inboxes w junk mail and impacts
server traffic to process messages.
-can be used to distribute malware and large scale phishing attacks
-modern gateways are very effective to block spam; inline
deployment of spam filters helps stop it before it hits the inbox
volumetric malware Ans: takes advantage of older unpatched
systems using common vulnerabilities
Zero-day malware Ans: A vulnerability that is discovered or
exploited before the vendor can issue a patch to fix it
-haven't been seen before and don't match any known malware
signatures
URL attacks Ans: urls that point to malicious websites or payloads
that are intended to trick users into clicking to download malware
© 2025 All rights reserved
, 2 | Page
Ransomware attack Ans: Blocking access to systems/files/data by
the means of encryption unless ransom is paid. Sometimes
combined with the threat to publish the data.
Data Exfiltration Ans: The unauthorized transfer of data. A more
basic definition is data theft.
-can lead to financial losses and have a long-lasting impact on an
organizations reputation
URL Phishing Ans: when cybercriminals use emails to direct their
victims to insert sensitive information on a fake website that looks
legit.
scamming Ans: cybercriminals use fraudulent schemes to defraud
victims or steal their identity by tricking them into disclosing
personal information
-organizations need to deploy both spam filters at the email
gateway and API-based inbox defense for effective protection
against scamming
spear phishing Ans: a highly targeted attack in which emails that
appear to be sent from a legitimate source are customized for
specific persons. An attacker researches the interests of the target
in order to create an email that tricks that specific person.
-API inbox defense to historical emails
domain impersonation Ans: attackers attempt to impersonate a
domain by using techniques such as typo-squatting, replacing one
or more letters in a legitimate email domain with a similar letter or
adding a hard-to notice letter to the legitimate email domain.
© 2025 All rights reserved
, 3 | Page
Brand Impersonation Ans: designed to impersonate a company or
a brand to trick their victims into responding and disclosing
personal or otherwise sensitive information
common types of brand impersonation Ans: service
impersonation- a phishing attack designed to impersonate a well-
known company or commonly used business application
brand highjacking- occurs when an attacker appears to use a
company's domain to impersonate a company or one of its
employees
extortion Ans: the practice of obtaining something, especially
money, through force or threats
Business Email Compromise (BEC) Ans: An impersonation attack in
which the attacker gains control of an employee's account and
uses it to convince other employees to perform fraudulent actions.
-defraud the company, its employees, customers, or partners
Conversation Hijacker Ans: cybercriminals insert themselves into
existing business conversations or initiate new conversations
based on info they've gathered from compromised email accounts
to steal money or personal info
lateral phishing Ans: attackers use recently highjacked accounts to
send phishing emails to unsuspecting recipients.
account takeover Ans: A type of fraud in which a hacker gains
access to a users credentials.
Email Gateway defense Ans: Monitors emails being sent into a
network and being sent outbound from that network
© 2025 All rights reserved
, 4 | Page
Inbound can prevent spam, which will help weed out malware
before it enters the network
Outbound can provide DLP, preventing the loss of sensitive data
Sandboxing Ans: Using a virtual machine to run a suspicious
program to determine if it is malware.
API-based CASB Ans: Solutions that do not interact directly with a
user but rather interact directly with the cloud provider through
the providers API.
Email Security Ans: • Spam - Unsolicited email messages
• Advertisements, phishing attacks, virus
spreaders
• Spam filters can be helpful
• Hijacked email
• Infected computers can become email
spammers
• You receive odd replies from other users
• You receive bounce messages from
unknown email addresses
© 2025 All rights reserved
Barracuda internship Questions and Correct
Answers
13 threats type Ans: spam, malware, data exfiltration, URL
phishing, scamming, spear phishing, domain impersonation, brand
impersonation, extortion, business email compromise,
conversational highjacking, lateral phishing, account takeover
Spam Ans: unsolicited, unwanted commercial email messages
also known as junk email
-lowers productivity by flooding inboxes w junk mail and impacts
server traffic to process messages.
-can be used to distribute malware and large scale phishing attacks
-modern gateways are very effective to block spam; inline
deployment of spam filters helps stop it before it hits the inbox
volumetric malware Ans: takes advantage of older unpatched
systems using common vulnerabilities
Zero-day malware Ans: A vulnerability that is discovered or
exploited before the vendor can issue a patch to fix it
-haven't been seen before and don't match any known malware
signatures
URL attacks Ans: urls that point to malicious websites or payloads
that are intended to trick users into clicking to download malware
© 2025 All rights reserved
, 2 | Page
Ransomware attack Ans: Blocking access to systems/files/data by
the means of encryption unless ransom is paid. Sometimes
combined with the threat to publish the data.
Data Exfiltration Ans: The unauthorized transfer of data. A more
basic definition is data theft.
-can lead to financial losses and have a long-lasting impact on an
organizations reputation
URL Phishing Ans: when cybercriminals use emails to direct their
victims to insert sensitive information on a fake website that looks
legit.
scamming Ans: cybercriminals use fraudulent schemes to defraud
victims or steal their identity by tricking them into disclosing
personal information
-organizations need to deploy both spam filters at the email
gateway and API-based inbox defense for effective protection
against scamming
spear phishing Ans: a highly targeted attack in which emails that
appear to be sent from a legitimate source are customized for
specific persons. An attacker researches the interests of the target
in order to create an email that tricks that specific person.
-API inbox defense to historical emails
domain impersonation Ans: attackers attempt to impersonate a
domain by using techniques such as typo-squatting, replacing one
or more letters in a legitimate email domain with a similar letter or
adding a hard-to notice letter to the legitimate email domain.
© 2025 All rights reserved
, 3 | Page
Brand Impersonation Ans: designed to impersonate a company or
a brand to trick their victims into responding and disclosing
personal or otherwise sensitive information
common types of brand impersonation Ans: service
impersonation- a phishing attack designed to impersonate a well-
known company or commonly used business application
brand highjacking- occurs when an attacker appears to use a
company's domain to impersonate a company or one of its
employees
extortion Ans: the practice of obtaining something, especially
money, through force or threats
Business Email Compromise (BEC) Ans: An impersonation attack in
which the attacker gains control of an employee's account and
uses it to convince other employees to perform fraudulent actions.
-defraud the company, its employees, customers, or partners
Conversation Hijacker Ans: cybercriminals insert themselves into
existing business conversations or initiate new conversations
based on info they've gathered from compromised email accounts
to steal money or personal info
lateral phishing Ans: attackers use recently highjacked accounts to
send phishing emails to unsuspecting recipients.
account takeover Ans: A type of fraud in which a hacker gains
access to a users credentials.
Email Gateway defense Ans: Monitors emails being sent into a
network and being sent outbound from that network
© 2025 All rights reserved
, 4 | Page
Inbound can prevent spam, which will help weed out malware
before it enters the network
Outbound can provide DLP, preventing the loss of sensitive data
Sandboxing Ans: Using a virtual machine to run a suspicious
program to determine if it is malware.
API-based CASB Ans: Solutions that do not interact directly with a
user but rather interact directly with the cloud provider through
the providers API.
Email Security Ans: • Spam - Unsolicited email messages
• Advertisements, phishing attacks, virus
spreaders
• Spam filters can be helpful
• Hijacked email
• Infected computers can become email
spammers
• You receive odd replies from other users
• You receive bounce messages from
unknown email addresses
© 2025 All rights reserved