CompTIA A+ Core 2 (220-1202)SecurityMedium

A user receives an email that appears to be from their bank, stating there's a security alert on their account and asking them to click a link to verify their details. The email contains the bank's logo and a seemingly legitimate sender address. However, the technician notices a slight misspelling in the domain name of the link provided. What type of social engineering attack is this?

  1. APretexting
  2. BBaiting
  3. CPhishing
  4. DVishing
Show answer & explanation

Correct answer: C. Phishing

Phishing is a social engineering attack that attempts to trick users into revealing sensitive information, usually via email, by impersonating a trustworthy entity. The scenario describes an email impersonating a bank, asking for credentials via a malicious link with a misspelled domain, which is a classic phishing tactic.

Why the other options are wrong

  • A. Pretexting involves creating a fabricated scenario (pretext) to obtain information, often through direct conversation, but the primary method here is a deceptive email link.
  • B. Baiting involves offering something enticing (like a free download or a USB drive) to lure victims into a trap, which is not described here.
  • D. Vishing is phishing conducted over the phone (voice phishing), not email.

Phishing

A type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (like usernames, passwords, credit card details) by disguising themselves as a trustworthy entity in an electronic communication, typically email.

  • Uses deceptive emails or messages
  • Impersonates a legitimate organization (e.g., bank, popular website)
  • Often includes malicious links or attachments
  • Goal is to steal credentials or install malware

Memory trick: Phishing reels you in with a fake email, Vishing uses your voice, and Pretexting uses a story.

More Security questions