CompTIA A+ Core 2 (220-1202)SecurityMedium

A user receives an email that appears to be from their company's HR department, asking them to click a link to update their benefits information. The email has a slightly off-brand logo, a generic greeting, and contains several grammatical errors. The link directs to a website that looks similar to the company's internal portal but has a different URL. What type of social engineering attack is MOST likely being attempted?

  1. APhishing
  2. BImpersonation
  3. CSmishing
  4. DVishing
Show answer & explanation

Correct answer: A. Phishing

This scenario describes a classic phishing attack. Phishing involves sending fraudulent emails or messages disguised as coming from a legitimate source, often to trick recipients into revealing sensitive information or clicking malicious links. The email's characteristics (off-brand logo, generic greeting, grammatical errors, suspicious URL) are common red flags for phishing.

Why the other options are wrong

  • B. Impersonation can be part of phishing, but 'phishing' specifically refers to the email-based attack described.
  • C. Smishing is phishing conducted via SMS text messages.
  • D. Vishing is phishing conducted over the phone (voice phishing).

Phishing

A type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information by impersonating a trustworthy entity in electronic communications, typically email.

  • Often uses fake websites or login pages.
  • Common red flags include generic greetings, grammatical errors, suspicious links/attachments.
  • Aims to steal credentials, financial info, or deploy malware.

Memory trick: Social engineers trick you through talk, text, or email.

More Security questions