CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsEasy
An employee receives an email that appears to be from the company's shipping vendor, addressed to them by name and referencing a recent order number. The email asks the employee to click a link to 'confirm delivery details.' Which type of attack is this?
- ASpear phishing
- BVishing
- CPretexting
- DTyposquatting
Show answer & explanationAnswer & explanation
Correct answer: A. Spear phishing
Spear phishing is a targeted email attack that uses personalized details (name, order number) to appear legitimate and trick a specific individual into clicking a malicious link.
Why the other options are wrong
- B. Vishing is voice-based, not email.
- C. Pretexting is a fabricated scenario used in social engineering, usually verbal, not the attack vector itself.
- D. Typosquatting involves registering lookalike domains, not personalized emails.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization, using personal or contextual details to increase credibility.
- More targeted than mass phishing
- Uses personal info like name, role, or recent activity
- Often precursor to BEC or credential theft
Memory trick: Spear = aimed at ONE fish with a personalized hook.