Complete Questions and Guide Answers
100% Verified Graded A+
1. Reconnaissance emails (recon emails)
Answer: used to check if the destination mailbox is in use so that it can be targeted in future phishing
attack
can be spam, social engineering or tracking pixels
2. Credential Harvesters
Answer: most common phishing emails targeting human
weaknesses to attempt to retrieve valid credentials
email will tell the recipient to click a button or URL, where they will typically be presented with a real-looking login portal
3. Social Engineering
Answer: the practice of exploiting a human as opposed to a system
malicious actors can convince employees that they are someone they know, or even someone in a higher position that has
,more power than them
4. Smishing
Answer: kind of phishing attack, where the attack vector is through a text message or SMS
best way to defend is user security awareness training and education
5. Vishing
Answer: kind of phishing attack, where the attack vector is through a phone call
best way to defend is user security awareness training and education
6. Whaling
Answer: highly-targeted phishing attack that looks to target individuals within management positions in an
organization
best way to defend is implementing DLP, marking external emails, train individuals to detect phishing emails
7. Malicious Attachments
Answer: malicious actors will send you Microsoft Oflce documents to bypass email scanners and to
seem less suspicious
include malicious macros, series of command and instructions, that download malware to the system
8. Hosted Malware
,Answer: method of hosting malware on websites and convincing users to click on a hyperlink, download a
file, and then run it
actor can create a malicious domain or compromise a legitimate site then host the malware
9. Spam Emails
Answer: messages that are unsolicited, unwanted, or unexpected but are not necessarily malicious in nature
should not be confused with malicious spam emails
10. False Positives
Answer: messages that have not been sent by a malicious actor and are instead legitimate emails that have
been incorrectly reported as malicious
11. Spear Phishing
Answer: when a malicious actor spends time before the phishing attack to gather information about their
specific target
makes it more convincing, increases the chances of the recipient clicking on the email and entering their credentials, or
opening an attachment
12. Impersonation
Answer: used by malicious actors to trick their target into thinking they are someone they know
makes them more likely to open and interact with a phishing email
, 13. Typosquatting
Answer: the act of impersonating a brand or domain name by misspelling it, such as missing letters or
including additional ones
14. Homographs
Answer: this attack exploits the fact that many ditterent characters look exactly alike the
problem is with how the characters are encoded using Unicode
virtually impossible for users to spot
15. Sender Spoofing
Answer: the process of making the sending address in an email look the same as a legitimate email to make
the recipients believe it is coming from a genuine sender
16. URL Shorteners
Answer: a tactic for disguising malicious URLs, short versions that simply redirect to the full URL
ex. bit.ly/2vyvczQ
17. Business Email Compromise (BEC)
Answer: A type of phishing attack where a threat actor impersonates a known source to obtain financial
advantage
18. Email Artifacts
Answer: - Sending Email Address