ISO-IEC-27001-LEAD-AUDITOR · Question #17
Phishing is what type of Information Security Incident?
The correct answer is B. Cracker/Hacker Attacks. Phishing is a type of information security incident that falls under the category of cracker/hacker attacks. Phishing is a form of fraud that uses deceptive emails or other messages to trick recipients into revealing sensitive information, such as passwords, credit card…
Question
Phishing is what type of Information Security Incident?
Options
- APrivate Incidents
- BCracker/Hacker Attacks
- CTechnical Vulnerabilities
- DLegal Incidents
How the community answered
(35 responses)- A6% (2)
- B91% (32)
- D3% (1)
Explanation
Phishing is a type of information security incident that falls under the category of cracker/hacker attacks. Phishing is a form of fraud that uses deceptive emails or other messages to trick recipients into revealing sensitive information, such as passwords, credit card numbers, bank account details, etc. Phishing emails often impersonate legitimate organizations or individuals and create a sense of urgency or curiosity to lure the victims into clicking on malicious links, opening malicious attachments or providing personal information. Phishing is a common and serious threat to information security, as it can lead to identity theft, financial loss, data breach, malware infection or other damages. ISO/IEC 27001:2022 requires the organization to implement awareness and training programs to make users aware of the risks of social engineering attacks, such as phishing, and how to avoid them (see clause A.7.2.2).
Topics
Community Discussion
No community discussion yet for this question.