CompTIA A+ Core 2 (220-1202)SecurityMedium
A user receives an email that appears to be from their bank, stating there's a security alert on their account and asking them to click a link to verify their details. The email contains the bank's logo and a seemingly legitimate sender address. However, the technician notices a slight misspelling in the domain name of the link provided. What type of social engineering attack is this?
- APretexting
- BBaiting
- CPhishing
- DVishing
Show answer & explanationAnswer & explanation
Correct answer: C. Phishing
Phishing is a social engineering attack that attempts to trick users into revealing sensitive information, usually via email, by impersonating a trustworthy entity. The scenario describes an email impersonating a bank, asking for credentials via a malicious link with a misspelled domain, which is a classic phishing tactic.
Why the other options are wrong
- A. Pretexting involves creating a fabricated scenario (pretext) to obtain information, often through direct conversation, but the primary method here is a deceptive email link.
- B. Baiting involves offering something enticing (like a free download or a USB drive) to lure victims into a trap, which is not described here.
- D. Vishing is phishing conducted over the phone (voice phishing), not email.
Phishing
A type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (like usernames, passwords, credit card details) by disguising themselves as a trustworthy entity in an electronic communication, typically email.
- Uses deceptive emails or messages
- Impersonates a legitimate organization (e.g., bank, popular website)
- Often includes malicious links or attachments
- Goal is to steal credentials or install malware
Memory trick: Phishing reels you in with a fake email, Vishing uses your voice, and Pretexting uses a story.