Ch.9 Protecting Devices and Networks Scenario 240 words

Phishing clue: urgency + login request = stop

Do not click; verify through a separate trusted channel or type the known address manually. The exam trap is that a realistic-looking invoice link can still be fake.

Audio

Listen to this page (beta)

Subtitles

The core idea is simple: any email that pressures you to act immediately and asks for login credentials is almost certainly a phishing attempt. Legitimate organisations rarely demand urgent logins via email links. Contrast this with a routine password reset email from your own IT department, which you can safely ignore until you initiate the process yourself. The danger lies in the fake invoice link that looks identical to a real one, but leads to a fraudulent login page designed to steal your credentials.

To spot these traps, first check the sender's email address carefully—phishers often use lookalike domains like 'amaz0n.com' instead of 'amazon.com'. Second, hover over any link without clicking to see the actual URL; if it doesn't match the claimed site, delete the email. Third, remember that genuine billing systems rarely send login requests via email; they direct you to log in on their official website. If you're unsure, open a new browser tab and type the known address yourself, rather than using any link in the message.

A quick mental test: if the email creates a false sense of urgency and asks for a login, treat it as guilty until proven innocent. For example, imagine you receive an email saying 'Your account will be suspended unless you verify now'—that's a classic phishing trigger. The safest move is always to verify through a separate channel, such as calling the company directly or logging in via a bookmarked URL.

Related flashcard

An email urges you to open an invoice link immediately and log in. What is the safest first move?

Do not click; verify through a separate trusted channel or type the known address manually.

Back to flashcard View all flashcards