CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsEasy

An employee receives an email that appears to be from the company's shipping vendor, addressed to them by name and referencing a recent order number. The email asks the employee to click a link to 'confirm delivery details.' Which type of attack is this?

  1. ASpear phishing
  2. BVishing
  3. CPretexting
  4. DTyposquatting
Show answer & explanation

Correct answer: A. Spear phishing

Spear phishing is a targeted email attack that uses personalized details (name, order number) to appear legitimate and trick a specific individual into clicking a malicious link.

Why the other options are wrong

  • B. Vishing is voice-based, not email.
  • C. Pretexting is a fabricated scenario used in social engineering, usually verbal, not the attack vector itself.
  • D. Typosquatting involves registering lookalike domains, not personalized emails.

Spear Phishing

A targeted phishing attack directed at a specific individual or organization, using personal or contextual details to increase credibility.

  • More targeted than mass phishing
  • Uses personal info like name, role, or recent activity
  • Often precursor to BEC or credential theft

Memory trick: Spear = aimed at ONE fish with a personalized hook.

More Threats, Vulnerabilities, and Mitigations questions