CompTIA A+ Core 2 (220-1202)SecurityMedium
A user receives an email that appears to be from their company's HR department, stating there's a security alert requiring them to click a link and log in to review a new policy. The link, however, points to a suspicious URL that is only slightly different from the legitimate company portal. Which social engineering attack is this an example of?
- AVishing
- BSmishing
- CPhishing
- DWhaling
Show answer & explanationAnswer & explanation
Correct answer: C. Phishing
Phishing is a type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information by impersonating a trustworthy entity in an electronic communication, typically email.
Why the other options are wrong
- A. Vishing is phishing conducted over phone calls, not email.
- B. Smishing is phishing conducted via SMS text messages, not email.
- D. Whaling is a targeted phishing attack aimed at high-profile individuals (e.g., CEOs), but the general term for this email-based deception is phishing.
Phishing
A social engineering attack where attackers attempt to trick individuals into revealing sensitive information (like usernames, passwords, and credit card details) by disguising themselves as a trustworthy entity in electronic communication, usually email.
- Uses deceptive emails, websites, or messages.
- Aims to steal credentials or install malware.
- Often relies on urgency, fear, or curiosity to manipulate victims.
Memory trick: Phishing is email, vishing is voice, smishing is SMS.