Weekly Knowledge Quiz • Difficulty 6/10

Phishing 101: Would You Take the Bait?

10 real-world scenarios covering phishing, social engineering, impersonation, suspicious links, payment fraud, and the little tricks scammers use to get you to do the work for them.

 
QUIZ START

Results

🎣 You Didn’t Take the Bait.

Perfect score — 100%.

Nicely done. You correctly identified every phishing and social engineering scenario in the quiz.

The important part: Be suspicious of urgency, independently verify unusual requests, and never rely on the communication you’re questioning to prove that the communication is legitimate.

You are officially annoying to scam.

🎣 The Phish Got One Through.

A perfect score is required to pass.

You missed at least one phishing or social engineering scenario. In the real world, that’s all it takes.

Time to brush up. Review the explanations for the questions you missed and give the quiz another shot.

Remember:

• Slow down when a message creates urgency, fear, or pressure.

• Independently verify unusual requests using contact information you already trust.

• A familiar name, email address, Caller ID, logo, or personal information does not prove who’s on the other end.

Brush up, try again, and don’t click anything weird in the meantime.

QUIZ START

#1. You receive an email from Microsoft saying your Microsoft 365 password expires today. There’s a button marked “Keep Current Password.” What’s the safest move?

Don’t use the communication you’re trying to authenticate as your method of authentication. Go to the service independently. A convincing logo, familiar wording, HTTPS, and even “microsoft” somewhere in a URL prove very little.

Previous
Next

#2. Your phone rings and Caller ID displays the name of your bank. The caller knows your name and the last four digits of your account. Is that enough to establish that the call is really from your bank?

Caller ID can be spoofed, and pieces of personal information can come from breaches, public records, social media, or previous scams. Call the bank yourself using a trusted number.

Previous
Next

#3. You receive an unexpected FedEx text saying a package couldn’t be delivered because of an incomplete address. It asks you to pay a 30-cent redelivery fee. What is the biggest danger?

The tiny charge is bait. The attacker may be after your card number, billing information, credentials, or other personal data—not the 30 cents.

Previous
Next

#4. An email from your company’s owner says: “I’m tied up in a meeting. I need you to buy four $200 Apple gift cards for a client. Send me photos of the codes.” What should happen next?

Replying to a compromised or impersonated account just asks the attacker to confirm the attacker’s own story. Verify unusual requests through a separate channel.

Previous
Next

#5. A website displaying the padlock/HTTPS symbol means the website itself is legitimate.

HTTPS means the connection between you and that website is encrypted. Criminals can obtain HTTPS certificates too. The padlock can mean you have a beautifully encrypted connection directly to the criminal.

Previous
Next

#6. A longtime vendor emails your accounting department: “We changed banks. Please use the attached instructions for all future ACH payments.” The email comes from the vendor’s real email account. What should accounting do?

Business email compromise often involves a real mailbox that has been taken over. An attacker controlling the account can read previous conversations, imitate writing styles, and reply convincingly. Payment changes deserve independent verification.

Previous
Next

#7. You suddenly receive six MFA approval requests on your phone. A few minutes later, “IT Support” calls and says there’s a problem with your account and asks you to approve the next request. What should you do?

This is a classic MFA-fatigue/social-engineering combination. The attacker may already have your password and needs you to approve the second factor.

Previous
Next

#8. Which email address should concern you the most?

Lookalike domains substitute characters or use similar spellings to exploit the fact that people tend to recognize the shape of a familiar name rather than inspect every character. Here, the “o” has been replaced with a zero.

Previous
Next

#9. Someone calls your office and says, “Hi, this is Mark from your IT company. John asked me to fix Linda’s email. I just need her Microsoft verification code.” He correctly knows John’s and Linda’s names. What does that prove?

Names, titles, coworkers, vendors and organizational relationships are often surprisingly easy to discover. Social engineering works because attackers collect enough real information to make the invented part of the story believable.

Previous
Next

#10. What is the defining feature of social engineering?

Sometimes there is no malicious attachment, fake website, or sophisticated malware at all. The vulnerability being exploited is human trust. The attacker creates urgency, authority, fear, curiosity, familiarity, or helpfulness and gets the victim to do the rest.

Previous
Finish