nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #17

Phishing is what type of Information Security Incident?

The correct answer is B. Cracker/Hacker Attacks. Phishing is a type of information security incident that falls under the category of cracker/hacker attacks. Phishing is a form of fraud that uses deceptive emails or other messages to trick recipients into revealing sensitive information, such as passwords, credit card…

Information Security Incident Management

Question

Phishing is what type of Information Security Incident?

Options

  • APrivate Incidents
  • BCracker/Hacker Attacks
  • CTechnical Vulnerabilities
  • DLegal Incidents

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    91% (32)
  • D
    3% (1)

Explanation

Phishing is a type of information security incident that falls under the category of cracker/hacker attacks. Phishing is a form of fraud that uses deceptive emails or other messages to trick recipients into revealing sensitive information, such as passwords, credit card numbers, bank account details, etc. Phishing emails often impersonate legitimate organizations or individuals and create a sense of urgency or curiosity to lure the victims into clicking on malicious links, opening malicious attachments or providing personal information. Phishing is a common and serious threat to information security, as it can lead to identity theft, financial loss, data breach, malware infection or other damages. ISO/IEC 27001:2022 requires the organization to implement awareness and training programs to make users aware of the risks of social engineering attacks, such as phishing, and how to avoid them (see clause A.7.2.2).

Topics

#phishing#social engineering#incident classification#hacker attacks

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice