A _______ attack comes in the form of deceptive emails or text messages that may ask you to install software or divulge personal information.
- (a)Spamming
- (b)Virus Signing
- (c)Phishing
- (d)Scanning
Correct — MPPSC's official key granted grace, accepting BOTH B (Virus Signing) AND C (Phishing). C, Phishing, is the term whose standard, well-documented definition matches the question exactly: a social-engineering attack delivered via deceptive email or text message that impersonates a trustworthy sender to trick the victim into installing malicious software or revealing personal/financial information. 'Virus Signing' (B) is not a standard, independently-defined cybersecurity term with a published meaning matching this description; MPPSC's key nonetheless credited it as part of the grace decision. This card records the official grace outcome for scoring accuracy while flagging that Phishing is the option whose definition is independently verifiable against the question text.
- (a)Spamming — Spamming is unsolicited bulk messaging (typically promotional); it does not require impersonating a trusted sender to extract credentials or install software, which is the behaviour this question describes.
- (d)Scanning — Scanning (e.g., port or vulnerability scanning) is a technical reconnaissance method attackers use to probe systems for weaknesses — it is not delivered as a deceptive email or text message.
Phishing is a social-engineering attack: the attacker impersonates a trustworthy party (a bank, employer, or service provider) via email, SMS, or message to trick the victim into clicking a malicious link, installing malware, or handing over credentials or personal data directly. It relies on deception and urgency rather than a technical exploit of the target system.
Cyber-security awareness questions test recognition of attack TYPES from a behavioural description — the giveaway phrase here, 'deceptive emails/texts' plus 'ask you to install software or divulge personal information,' is the standard definition of phishing.
- Phishing = a social-engineering attack via deceptive email/SMS/message impersonating a trusted sender.
- Goal: trick the victim into installing malware or revealing personal/financial information.
- Variants include spear-phishing (targeted at a specific individual/organisation) and smishing (phishing via SMS).
- Different from spamming (unsolicited bulk messaging) and scanning (technical probing of systems for vulnerabilities).
MPPSC's official key granted grace for both B and C; C (Phishing) is the term whose standard definition matches the question.
- Confusing phishing (a deceptive message trying to extract data) with spamming (unsolicited bulk messaging that need not impersonate anyone).
- Assuming a described attack must match only one option — official keys can grant grace for more than one accepted answer.
MPPSC/UPSC cyber-security items typically give a behavioural description and ask you to name the attack type — lock the phrase 'deceptive email/message asking you to install software or reveal information' to Phishing.
The terms 'WannaCry, Petya and EternalBlue' sometimes mentioned in the news recently are related to
- (a) Exoplanets
- (b) Cryptocurrency
- (c) Cyber attacks
- (d) Mini satellites
Answer(c) Cyber attacks
Both test naming/classifying a cyber-attack from context — UPSC 2018 asks what WannaCry/Petya/EternalBlue relate to (cyber attacks), this question asks what a deceptive-email/text attack is called (phishing); same broad theme of identifying cyber-attack terminology, though the specific mechanisms (ransomware vs social engineering) differ.
- practice — not a real PYQ
A phishing attack targeted at a specific individual or organisation, often researched in advance by the attacker, is known as:
- (a)Smishing
- (b)Spear-phishing
- (c)Vishing
- (d)Spamming
Answer(b) Spear-phishing — a phishing attack customised for a specific target.
- practice — not a real PYQ
Which of the following is India's nodal agency for responding to cyber-security incidents such as phishing attacks?
- (a)NIC
- (b)CERT-In
- (c)UIDAI
- (d)TRAI
Answer(b) CERT-In (Indian Computer Emergency Response Team) — the nodal agency for cyber-security incident response in India.