A fraudulent email asks a student to click a link and sign in to keep the student's school account active. What type of attack is this?
Phishing
What security control requires a user to provide more than one type of proof before gaining access to an account?
Multifactor authentication or MFA.
Which web protocol encrypts browser traffic between the user and the legitimate website: HTTP or HTTPS?
HTTPS.
What AI-enabled attack creates convincing speech that imitates a real person's voice?
Voice cloning.
What AI-assisted process sorts security events into likely malicious and likely harmless groups?
Alert triage.
A caller pretends to be from the help desk and asks for a password reset code. What type of social engineering uses a phone call or voice message?
Vishing
An automated tool tries every possible character combination against one account. What password attack is this?
A brute-force attack.
A coffee shop has two Wi-Fi networks with nearly identical names, and one was created by an attacker. What wireless attack is this?
An evil-twin attack.
Crafted instructions tell a chatbot to ignore its rules and reveal confidential information. What attack is this?
Prompt injection.
What term describes a system performing one security task without a person carrying out every step?
Automation.
An attacker registers micros0ft.com and builds a fake sign-in page. What attack uses this look-alike domain?
Tyosquatting
An attacker tries Summer2026 against hundreds of school accounts, using only one attempt per account. What attack is this?
Password spraying.
A person drives through a neighborhood recording SSIDs, security types, and wireless signal ranges. What activity is this?
Wardriving.
An attacker uses AI to scan social media and public websites, then summarize useful details about a target. What AI-enabled activity is this?
AI reconnaissance.
An AI recommends closing a firewall port. Why should a qualified technician review and test the change before deployment?
The recommendation may be wrong or may interrupt a legitimate service; the technician must validate the evidence, context, and impact.
A fake principal threatens a student with immediate suspension unless the student reveals a login code. Name the manipulation tactic and the sensitive item being targeted.
Intimidation; a one-time password or authentication code.
An attacker collects a teacher's birthday, pet's name, school, and favorite team, then automatically tests related password guesses. What attack is this?
A targeted dictionary attack.
An attacker develops a new exploit for a vulnerability that is not publicly documented. What skill level does this suggest, and what type of vulnerability may be involved?
A high-skilled adversary exploiting a zero-day or previously undocumented vulnerability.
A caller sounds exactly like the superintendent and demands an emergency transfer. Give two independent verification methods that do not rely on the call itself.
Use a private shared verification word and contact the superintendent through a known number or separate trusted channel.
A monitoring tool detects likely ransomware and immediately isolates the device. What defensive use of AI is shown, and what human responsibility remains?
Automated corrective response; staff must review the evidence, preserve necessary evidence, confirm the action, monitor results, and escalate when appropriate.
An employee receives an urgent email from a person claiming to be a new vendor. The message uses a convincing business story, links to paypa1.com, and requests immediate payment. Identify the three social-engineering elements.
Pretexting, typosquatting, and urgency.
A school sees two patterns: hundreds of usernames each receive one guess for Welcome1, while one administrator account receives thousands of different guesses. Identify both attacks in order.
Password spraying, followed by a brute-force attack.
A traveler joins Hotel_Guest instead of the staff-confirmed Hotel-Guest network. The fake network operator can see connection metadata, but the traveler's banking page uses valid HTTPS. Name the attack and explain what HTTPS does and does not protect.
This is an evil-twin attack. HTTPS encrypts the browser's connection to the legitimate bank website, limiting direct reading or alteration of that content, but it does not make the user anonymous or make the fake network trustworthy.
An attacker writes hidden instructions inside a document so an AI assistant will disclose its system instructions. The attacker also corrupts the assistant's reference database with false records. Identify both attacks and distinguish when each one acts.
The hidden instructions are prompt injection, which manipulates the system during use. The false records are data poisoning, which corrupts training or reference data and influences later behavior.
Design a four-step orchestration playbook for a high-confidence malicious login alert.
One acceptable response: enrich the alert with threat information, disable or secure the account and revoke sessions, block the malicious source or isolate the affected device, and open an incident ticket for human investigation.