Social Engineering
Password Attacks and Authentication
Adversaries and Wireless Attacks
AI-Augmented Attacks
100

This social engineering tactic creates a deadline or time-sensitive situation to pressure someone into acting quickly.

What is urgency?

100

This requires a second form of authentication to make accounts more secure.

What is multifactor authentication?

100

This type of adversary uses tools created by others and generally does not understand how the tools work.

What is a script kiddie?

100

This is when attackers can use existing voice and image samples to create this digital clone of a person.

What is impersonation?

200

An attacker sends an employee a message claiming to be their supervisor and says they will face consequences if they do not immediately provide a login code. This tactic uses fear of negative consequences.

What is intimidation?

200

Seeing hundreds of failed login attempts from an unfamiliar device within a few minutes would be a strong indicator of this type of attack.

What is an online password attack?

200

An attacker creates a wireless network with an SSID that looks identical or nearly identical to a legitimate network in order to trick victims into connecting.

What is an evil twin attack?

200

This is how LLM can make the language of phishing emails more convincing. 

What is they can make it seem like the messages are written by a native speaker of the target's native language?

300

An attacker calls an employee pretending to be an IT technician and gives a believable reason for needing the employee's information. This social engineering attack is known by this term.

What is pretexting?

300

An attacker gathers a target's pet's name, birthday, and family members' names and uses that information to generate possible passwords. This demonstrates how attackers take advantage of this weakness.


What are predictable password patterns / weak authentication?

300

An attacker drives around an area searching for wireless network beacons and determining where wireless signals extend outside a building. This activity is known by this term.

What is war driving?

300

An attacker creates or modifies websites containing false information so that AI systems may later include that false information in their training data. How does this influence the output of AI systems?

What is AI may repeat or spread the false information?

400

A victim provides an attacker with this type of authentication information after receiving a convincing message. The attacker may then be able to log in as the victim.

What is a one-time password or authentication login code?

400

A user wants to make their authentication significantly stronger. Name two improvements they should make to their authentication practices.

What are using long, random, unique passwords and enabling MFA?

400

A coffee shop's legitimate Wi-Fi suddenly becomes unavailable because an attacker is transmitting a strong electromagnetic signal on the same frequency. Identify the attack and the type of attack it represents.

What is jamming, and it is a denial-of-service (DoS) attack?

400

An employee enters confidential company information into an AI chatbot. According to the security guidance, why could this create a security risk?

What is that sensitive information entered into an AI tool could potentially be retained or used for training and later extracted?

500

An employee receives a message saying, "Your account will be deleted in 10 minutes unless you click this link and verify your information." Identify two psychological tactics being used and explain how they influence the victim.

What are urgency and intimidation?

500

An employee uses the password Boston2025! on several websites. Explain two different weaknesses with this password and identify a technology that could help the employee create and manage stronger passwords.

What are a predictable password pattern and password reuse; a password manager could generate and store strong, unique passwords.

500

A person connects to an evil twin network and visits a website using HTTPS. The attacker can capture the victim's network traffic, but this protocol provides an important limitation on what the attacker can read. What is the limitation?

What is that the attacker cannot read traffic protected by HTTPS encryption?

500

A bank uses voice authentication. An attacker uses AI to clone a customer's voice and attempts to access the customer's account. Identify two recommended protections that could reduce the risk of this attack.

What are enabling MFA and establishing a shared secret/secret phrase for high-stakes identity verification?