▸case-05 We are designing custom SIEM detection rules for email gateway logs. Most phishing filters rely heavily on natural language processing of body text, but quishing emails often leave the body blank or include only a sign-off. What rule condition should we construct to detect this specific pattern? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 Our SOC wants to create high-confidence detection rules for internal team spoofing attacks involving QR codes. Analysts suggest matching on any email from an external domain claiming to be IT support. What specific theme and requirement combination should be encoded in our SIEM alert? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 During an incident investigation, analysts discovered a QR code whose extracted link points to an intermediate landing page containing a second QR code. What term describes this evasion mechanism and how should link inspection handle it? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 When configuring our email gateway OCR pipeline for image analysis, administrators want to restrict processing to PNG only to reduce latency. Which specific set of image file extensions must be enabled for OCR scanning to ensure full coverage? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 An employee received a text message on their mobile phone claiming their bank account was locked, containing a shortlink. Outline the immediate SOC incident response steps for investigating an SMS phishing (smishing) alert. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 Attackers are embedding QR code images inside attached PDF documents rather than the email body to bypass standard inline image scanners. How should our email gateway processing workflow be updated to handle this vector? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 Our IT administration team needs to push a mandatory corporate HR mobile app to 500 iOS and Android smartphones via our MDM solution. What steps are required to construct an app distribution profile in an MDM? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 We are auditing our security controls to ensure proper coverage against QR code phishing across both our email gateway and mobile endpoints. Please generate a detailed operational procedure covering image/attachment scanning configuration, link reputation and sandbox verification, mobile threat defense setup, and the quantitative validation criteria needed to confirm our quishing defenses are functioning effectively. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 We need to publish strict email authentication records for our domain example.com to prevent spoofing. Please outline the DNS record formats for SPF, DKIM, and DMARC enforcement. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 To ensure that user navigation resulting from mobile QR code scanning passes through corporate web inspection, what network enforcement mechanism should be configured on the mobile device via MDM? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 If an employee scans a malicious QR code on a mobile device enrolled in MDM, what network proxy control should be active on the device to block credential harvesting? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 We noticed attackers rendering QR matrix blocks using monospace text characters in plain text emails rather than attaching PNG or JPG image files. Many security filters miss this because no image parser is triggered. What specific detection capability should we enable in our email security gateway configuration to catch text-rendered QR codes? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 Attackers are bypassing our email gateway's single-image OCR scanner by cutting QR codes into two adjacent image files in HTML tables, which look whole only when rendered in Outlook. How should our security Gateway or threat hunting rules handle split image evasion techniques? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 Once our gateway extracts a destination URL from a decoded QR code, how should the URL inspection pipeline handle that link compared to standard plain-text URLs in email bodies? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 When employees scan a QR code from an email on their corporate smartphones, standard web filtering on the laptop is bypassed. What mobile security mechanism or scanning assessment tool should be deployed on managed mobile devices to evaluate QR destination safety prior to navigation? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 Our security team wants to enable inbound link protection for plain text HTML links in external emails using our gateway's URL rewriting feature. How should link rewriting be configured for standard text hyperlinks in email bodies? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 We want to reduce false positives by filtering SIEM alerts for QR codes in email attachments. What sender behavior metric combined with QR code image presence forms a strong indicator of a quishing attack? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 Our organization is experiencing an uptick in emails containing embedded QR codes designed to steal credentials. I need a comprehensive, multi-phase implementation plan outlining how to configure our email security system to process image-based QR codes, analyze extracted destination links, enforce mobile-side defenses, write effective SIEM alert logic, and conduct user awareness simulations. Please format the response as a structured technical guide with clear deployment phases. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 Our CISO requested measurable KPIs to confirm our quishing defense program is effective following our recent gateway and awareness rollout. What specific quantitative thresholds should we set for user reporting rates and false positive rates? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 When tuning our SIEM threat hunting queries for quishing campaigns, what specific non-MFA business lures commonly accompany QR code phishing emails? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Traditional OCR engine rules often fail when attackers add artistic background shading or custom logos to QR codes. What architecture approach combines computer vision, text recognition, and language analysis to detect quishing? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 What text-based sentiment indicator when combined with the presence of a QR code image should trigger an elevated severity SIEM alert? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |