Questions: Identifying Phishing and Social Engineering Attempts

5 questions to test your understanding

Score: 0 / 5
Question 1 Multiple Choice

You receive an email with the display name 'PayPal Security Team' warning that your account has been locked. The From field shows: PayPal Security Team <[email protected]>. Which signal is the most reliable indicator that this is phishing?

AThe urgent tone about your account being locked
BThe domain 'paypa1-alerts.com' does not match PayPal's actual domain
CThe email includes a link to click to restore access
DThe message arrived unsolicited without you contacting PayPal first
Question 2 Multiple Choice

You receive a suspicious email claiming your bank account was compromised. The email includes a toll-free phone number to call immediately. What is the safest response?

ACall the number in the email — it is safer than clicking a link
BReply to the email asking for proof of identity before calling
CGo directly to your bank's official website and find the support number there, then call that number
DForward the email to your bank's email address listed in the suspicious message
Question 3 True / False

A phishing email that addresses you by your real name (e.g., 'Dear Griffin') is probably legitimate, since attackers primarily know your email address and use generic greetings.

TTrue
FFalse
Question 4 True / False

The artificial urgency in phishing messages — 'Your account will be suspended in 24 hours!' — is deliberately designed to prevent you from pausing to verify the message's legitimacy.

TTrue
FFalse
Question 5 Short Answer

Why does the display name in an email's 'From' field provide almost no security value, and what should you examine instead?

Think about your answer, then reveal below.