Test on Cybercrime and Cybersecurity Law

Cybercrime and Cybersecurity Law: Student Overview & Analysis

Question 1 of 50%

A professional-looking website on a free hosting server is generally considered a credible sign of a trustworthy online merchant.

Test: Cybercrime types & taxonomy, Illegal content & privacy protection, Security practice & education, Legal & Regulatory Frameworks: Cybercrime Law, Cybersecurity & Network Defense Fundamentals, Legal & Regulatory Frameworks: Cyberspace & Internet Law, Legal & Regulatory Frameworks: Regional & International Cyber Law, Law, regulation & compliance, Legal & Regulatory Frameworks: ISP Liability & Services Law, Legal & Regulatory Frameworks: Data Retention & Privacy Law, Privacy, Data Protection & Compliance - GDPR Core, Privacy, Data Protection & Compliance - IP & Network Privacy, Privacy & Cybersecurity Practices, Privacy, Data Protection & Compliance - Digital Privacy & Platforms, Digital Forensics & Incident Response, Privacy, Data Protection & Compliance - Google & Platform Data, Cybercrime operations & techniques, IoT & Embedded Device Security, Attack Techniques & Exploits, Identity & Access Management, Botnets & Malware, Malware Legal & Crime, Malware Types, Mobile Malware, Ransomware & Defense, Email Fraud & BEC, Online fraud & scam prevention, Phishing & Social Engineering, Cybercrime & Threat Analysis, Legal & Regulatory Frameworks: Intellectual Property & Copyright Law, Child Safety & Online Protection

20 questions

Question 1: A professional-looking website on a free hosting server is generally considered a credible sign of a trustworthy online merchant.

A. Yes

B. No

Explanation: The study materials state that if a website is located on a free hosting server, it is a sign of unprofessionalism and will not create a credible impression, regardless of its appearance.

Question 2: According to the study materials, which of the following is a crucial guideline for users to avoid fraudulent practices related to advance payments?

A. Always make advance payments when offered goods at a very advantageous price.

B. Only pay in advance if you are certain you are dealing with a trusted supplier.

C. Sending money via Western Union is generally a safe method for advance payments.

D. It is acceptable to send money to a private bank account for advance payments if the company promises delivery.

Explanation: The study materials explicitly state: 'Only make a payment in advance if you are sure you are dealing with a trusted supplier.' It also warns against offers that seem 'too good to be true,' notes that 'A request for payment by Western Union is particularly suspicious,' and advises 'For bank transfers, never send money to private accounts unless it is the account of the selling company.'

Question 3: A spear phishing attack is primarily characterized by its broad, indiscriminate distribution to a large, unspecified number of potential victims, similar to a carpet bombing strategy.

A. Yes

B. No

Explanation: The study materials state that 'Spear phishing is a precisely targeted attack, unlike phishing, which is a rather widespread (random) attack.' Phishing, not spear phishing, is compared to 'carpet bombing' and 'targets a relatively unspecified number of victims.'

Question 4: According to the study materials, which of the following accurately describes a characteristic of phishing in the *broad sense*?

A. It strictly requires a user to visit a fraudulent site and then fill in login information directly.

B. It encompasses any fraudulent conduct intended to inspire confidence in a user, reduce vigilance, or force acceptance of an attacker's scenario.

C. It primarily involves providing a user with a message or redirecting them to a page typically containing malware that collects data, without necessarily requiring them to fill in information.

D. It is exclusively concerned with obtaining credit card numbers and PINs through fake internet banking websites.

Explanation: Phishing in a broad sense is defined as any fraudulent conduct intended to inspire confidence in a user, reduce his/her vigilance or otherwise force him/her to accept a scenario prepared in advance by an attacker. In this broad sense, the user is no longer required to fill in the data, but is provided with a message or redirected to a page typically containing malware that collects the data. The first option describes phishing in a narrow sense, and the fourth option is too restrictive, as phishing in both senses aims for various types of user information, not just credit cards and PINs, and is not exclusive to internet banking sites.

Question 5: In the Czech Republic, actions involving cracking are primarily punishable under Section 182 (Violation of the secrecy of transported messages) of the Criminal Code.

A. Yes

B. No

Explanation: The study materials state that actions of an offender involving cracking, with the intention of obtaining information and subsequent unauthorized use, fulfill the objective elements of a criminal offense under Section 230 (1) or (2) (Unauthorized access to computer system and information carrier) of the Criminal Code. Section 182 is mentioned in relation to illegal interception and recording of telecommunications traffic (sniffing), not cracking.