Which of the following is a type of cyber attack that involves tricking users into revealing sensitive information?
Explanation & Solution
The correct answer is (A) Phishing attack.
- Phishing is a malicious form of social engineering where attackers impersonate legitimate organizations or trusted entities through electronic communications—predominantly deceptive emails or fraudulent websites—to trick unsuspecting users into divulging sensitive information such as login credentials, credit card numbers, and personal identification numbers.
- In the context of cybersecurity and the Information Technology (IT) framework, phishing represents a critical human-layer vulnerability that bypasses technical security controls by exploiting psychological manipulation rather than software bugs.
- Option (B) SQL Injection is a code injection technique that exploits security vulnerabilities in an application's database layer; Option (C) Denial of Service (DOS) is an attack aimed at making a machine or network resource unavailable to its intended users; therefore, options (B) and (C) are incorrect as they do not involve tricking users into revealing sensitive information through social engineering.
हिंदी में प्रश्न एवं आदर्श उत्तर
निम्नलिखित में से कौन-सा साइबर हमले का एक प्रकार है जिसमें उपयोगकर्ता को संवेदनशील सूचना को ज़ाहिर करने के लिए छल करना शामिल है?
सही उत्तर (A) फ़िशिंग हमला है।
- फ़िशिंग (Phishing) सोशल इंजीनियरिंग का एक दुर्भावनापूर्ण रूप है जिसमें हमलावर वैध संगठनों या विश्वसनीय संस्थाओं का रूप धारण करके इलेक्ट्रॉनिक संचार—मुख्य रूप से भ्रामक ईमेल या फर्जी वेबसाइटों—के माध्यम से उपयोगकर्ताओं को पासवर्ड, क्रेडिट कार्ड नंबर और व्यक्तिगत पहचान संख्या जैसी संवेदनशील सूचनाओं को ज़ाहिर करने के लिए छल करते हैं।
- साइबर सुरक्षा और सूचना प्रौद्योगिकी (IT) ढांचे के संदर्भ में, फ़िशिंग एक महत्वपूर्ण मानवीय-स्तर की कमज़ोरी को दर्शाता है जो सॉफ्टवेयर की कमियों के बजाय मनोवैज्ञानिक हेरफेर का फायदा उठाकर तकनीकी सुरक्षा नियंत्रणों को बायपास करती है।
- विकल्प (B) SQL इंजेक्शन एक कोड इंजेक्शन तकनीक है जो किसी एप्लिकेशन की डेटाबेस परत में सुरक्षा कमियों का फायदा उठाती है; विकल्प (C) डिनायल ऑफ सर्विस (DOS) एक ऐसा हमला है जिसका उद्देश्य किसी मशीन या नेटवर्क संसाधन को उसके इच्छित उपयोगकर्ताओं के लिए अनुपलब्ध बनाना है; अतः विकल्प (B) और (C) गलत हैं क्योंकि उनमें उपयोगकर्ताओं को सामाजिक इंजीनियरिंग के माध्यम से संवेदनशील जानकारी प्रकट करने के लिए छल करना शामिल नहीं है।