CompTIA A+ Core 2 (220-1202)SecurityMedium

A user receives an email that appears to be from their company's HR department, stating there's a security alert requiring them to click a link and log in to review a new policy. The link, however, points to a suspicious URL that is only slightly different from the legitimate company portal. Which social engineering attack is this an example of?

  1. AVishing
  2. BSmishing
  3. CPhishing
  4. DWhaling
Show answer & explanation

Correct answer: C. Phishing

Phishing is a type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information by impersonating a trustworthy entity in an electronic communication, typically email.

Why the other options are wrong

  • A. Vishing is phishing conducted over phone calls, not email.
  • B. Smishing is phishing conducted via SMS text messages, not email.
  • D. Whaling is a targeted phishing attack aimed at high-profile individuals (e.g., CEOs), but the general term for this email-based deception is phishing.

Phishing

A social engineering attack where attackers attempt to trick individuals into revealing sensitive information (like usernames, passwords, and credit card details) by disguising themselves as a trustworthy entity in electronic communication, usually email.

  • Uses deceptive emails, websites, or messages.
  • Aims to steal credentials or install malware.
  • Often relies on urgency, fear, or curiosity to manipulate victims.

Memory trick: Phishing is email, vishing is voice, smishing is SMS.

More Security questions