A teenager downloads a hacking tool from a forum and uses it to deface a school website, without understanding how the tool works. What type of adversary is this?
An employee at a tech company begins leaking confidential data to a competitor after being passed over for a promotion. What type of threat does this represent?
A group of hacktivists disables a government website to protest environmental policies. What motivates this type of adversary?
A coordinated cyberattack disables a city's water treatment system, causing widespread panic. What type of adversary is most likely responsible?
A transnational criminal organization steals proprietary software from a tech company and sells it on the dark web. What is their primary motivation?
A highly skilled team uses advanced malware to infiltrate a rival nation's defense systems. Who are they likely working for?
An employee receives a text message claiming to be from IT support, asking them to click a link to reset their password. What type of attack is this?
A fake login page mimics a bank’s website and captures username and password. What type of attack is this?
An attacker intercepts communication between a user and a website, altering the data before passing it along. What is this called?
A user receives an email from someone claiming to be their manager, demanding immediate action or face consequences. What psychological tactic is being used?
An attacker uses a believable story to initiate a conversation with a target and gain their trust. What tactic is this?
A website’s input field allows users to enter text, but an attacker enters code that alters the site’s behavior. What type of attack is this?
A company’s website is overwhelmed by traffic from thousands of devices, making it inaccessible. What kind of attack is this?
An attacker listens in on unencrypted network traffic to collect sensitive data. What is this called?
Before launching an attack, a hacker spends weeks gathering information from public sources about a company’s employees and systems. What phase is this?
An attacker gains access to a system using stolen credentials. What phase of the attack is this?
After compromising a device, an attacker installs a remote access trojan to maintain control. What phase is this?
An attacker jumps from one compromised device to another, seeking higher-level access. What phase is this?
An attacker exfiltrates sensitive data and deletes critical files from a server. What phase is this?
After completing an attack, the adversary deletes log files and removes malware to avoid being caught. What phase is this?