CompTIA A+ Core 2 (220-1202)SecurityMedium
A user receives an email that appears to be from their company's HR department, asking them to click a link to update their benefits information. The email has a slightly off-brand logo, a generic greeting, and contains several grammatical errors. The link directs to a website that looks similar to the company's internal portal but has a different URL. What type of social engineering attack is MOST likely being attempted?
- APhishing
- BImpersonation
- CSmishing
- DVishing
Show answer & explanationAnswer & explanation
Correct answer: A. Phishing
This scenario describes a classic phishing attack. Phishing involves sending fraudulent emails or messages disguised as coming from a legitimate source, often to trick recipients into revealing sensitive information or clicking malicious links. The email's characteristics (off-brand logo, generic greeting, grammatical errors, suspicious URL) are common red flags for phishing.
Why the other options are wrong
- B. Impersonation can be part of phishing, but 'phishing' specifically refers to the email-based attack described.
- C. Smishing is phishing conducted via SMS text messages.
- D. Vishing is phishing conducted over the phone (voice phishing).
Phishing
A type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information by impersonating a trustworthy entity in electronic communications, typically email.
- Often uses fake websites or login pages.
- Common red flags include generic greetings, grammatical errors, suspicious links/attachments.
- Aims to steal credentials, financial info, or deploy malware.
Memory trick: Social engineers trick you through talk, text, or email.