CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

An organization's threat intelligence team observes that employees at a manufacturing firm frequently visit a niche industry forum for technical specifications. Attackers compromise that forum and inject malicious code that only executes against visitors from the firm's IP range. Which type of attack is this?

  1. APharming
  2. BBusiness email compromise
  3. CCredential stuffing
  4. DWatering hole attack
Show answer & explanation

Correct answer: D. Watering hole attack

Compromising a website that a specific target group is known to frequent, then serving malicious content selectively to that group, is the defining behavior of a watering hole attack.

Why the other options are wrong

  • A. Pharming redirects users to fraudulent sites via DNS/hosts manipulation, not compromising a legitimate site the target already visits.
  • B. BEC involves impersonating executives via email to commit fraud, not compromising a forum.
  • C. Credential stuffing uses leaked credentials against login portals, unrelated to compromising a third-party site.

Watering Hole Attack

An attack strategy where adversaries compromise a website known to be frequented by a specific target group, infecting visitors from that group.

  • Targets are identified by common online behavior/interests
  • Malicious payload often filtered by IP range or user agent
  • Mitigated by web filtering, endpoint protection, and network segmentation

Memory trick: Poison the watering hole and wait for the herd to drink.

More Threats, Vulnerabilities, and Mitigations questions