10 real-world scenarios covering phishing, social engineering, impersonation, suspicious links, payment fraud, and the little tricks scammers use to get you to do the work for them.
Perfect score — 100%.
Nicely done. You correctly identified every phishing and social engineering scenario in the quiz.
The important part: Be suspicious of urgency, independently verify unusual requests, and never rely on the communication you’re questioning to prove that the communication is legitimate.
You are officially annoying to scam.
A perfect score is required to pass.
You missed at least one phishing or social engineering scenario. In the real world, that’s all it takes.
Time to brush up. Review the explanations for the questions you missed and give the quiz another shot.
Remember:
• Slow down when a message creates urgency, fear, or pressure.
• Independently verify unusual requests using contact information you already trust.
• A familiar name, email address, Caller ID, logo, or personal information does not prove who’s on the other end.
Brush up, try again, and don’t click anything weird in the meantime.
Don’t use the communication you’re trying to authenticate as your method of authentication. Go to the service independently. A convincing logo, familiar wording, HTTPS, and even “microsoft” somewhere in a URL prove very little.
Caller ID can be spoofed, and pieces of personal information can come from breaches, public records, social media, or previous scams. Call the bank yourself using a trusted number.
The tiny charge is bait. The attacker may be after your card number, billing information, credentials, or other personal data—not the 30 cents.
Replying to a compromised or impersonated account just asks the attacker to confirm the attacker’s own story. Verify unusual requests through a separate channel.
HTTPS means the connection between you and that website is encrypted. Criminals can obtain HTTPS certificates too. The padlock can mean you have a beautifully encrypted connection directly to the criminal.
Business email compromise often involves a real mailbox that has been taken over. An attacker controlling the account can read previous conversations, imitate writing styles, and reply convincingly. Payment changes deserve independent verification.
This is a classic MFA-fatigue/social-engineering combination. The attacker may already have your password and needs you to approve the second factor.
Lookalike domains substitute characters or use similar spellings to exploit the fact that people tend to recognize the shape of a familiar name rather than inspect every character. Here, the “o” has been replaced with a zero.
Names, titles, coworkers, vendors and organizational relationships are often surprisingly easy to discover. Social engineering works because attackers collect enough real information to make the invented part of the story believable.
Sometimes there is no malicious attachment, fake website, or sophisticated malware at all. The vulnerability being exploited is human trust. The attacker creates urgency, authority, fear, curiosity, familiarity, or helpfulness and gets the victim to do the rest.