Microsoft Certified Security Compliance And Identity Fundamentals · Free Practice Question Easy

Question 11

Scenario: Anvil is a private military firm founded by Billy Russo with the purpose of providing military and security services. The company specializes in its activity in military contract services, such as personal protection, convoy security, and tactical operations.

To keep ahead of the technological curve, Billy has adopted Microsoft as a core system for the company. Anvil has had several phishing scam attempts from outside the company.

What type of security risk does a phishing scam pose?

  • A

    Authentication risk

  • B

    Identity risk

  • C

    Ethical risk

  • D

    Physical risk

Reveal correct answer

Correct answer: B

Explanation

A phishing scam is an example of an identity attack.

Common identity attacks

Some of the most common types of security threats that organizations face today are identity attacks. These attacks are designed to steal the credentials used to validate or authenticate that someone or something is who they claim to be. The result is identity theft.

Password-based attacks

Password-based attacks include password spray attacks and brute force attacks. A password spray attack attempts to match a username against a list of weak passwords.

Brute force attacks try many passwords against one or more accounts, sometimes using dictionaries of commonly used passwords. When a user has assigned a weak password to their account, the hacker will find a match, and access that account.



Phishing

A phishing attack is when a hacker sends an email that appears to come from a reputable source. The email contains a credible story, such as a security breach, instructing the user to sign in and change their password. Instead of going to a legitimate website, the user is directed to the scammer’s website where they enter their username and password. The hacker has now captured the user’s identity, and their password.

Although many phishing scam emails are badly written and easy to identify, when users are busy or tired, they make mistakes and are more easily deceived. As hackers become more sophisticated, their phishing emails become more difficult to identify.

Spear phishing

A spear phishing scam is a variant on phishing. Hackers build databases of information about users, which can be used to create highly credible emails. The email may appear to come from someone in your organization who is requesting information. Although careful scrutiny might uncover the fraud, users may not read it carefully enough and send the requested information or login to the website before they realize the fraud. This practice is called spear phishing because it's highly targeted.

To protect against all types of identity attacks, robust identity security and monitoring is needed. Risk detections in Azure AD Identity Protection include any identified suspicious actions related to user accounts.

There are two types of risk: user risk and sign-in risk. User risk represents the probability that a given identity or account is compromised. Sign-in risk represents the probability that a given authentication request isn't authorized by the identity owner.

https://www.microsoft.com/security/blog/2020/07/15/prevent-identity-attacks-azure-active-directory/

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need