Phishing is generally broad and indiscriminate, using mass emails, messages, or fake websites to trick many users into disclosing credentials, clicking malicious links, or opening harmful attachments. Spear phishing is targeted. It is directed at specific individuals, roles, departments, or organizations and often uses personalized information to appear credible. Option B is incorrect because both phishing and spear phishing can use email, text messages, social media, or other communication methods. Option C incorrectly describes the distinction; both rely heavily on social engineering. Option D is also wrong because both may aim to obtain credentials, financial information, or access. Internal auditors should evaluate user awareness, email filtering, incident reporting, and authentication controls. Therefore, Option A is correct.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit