CompTIA Tech+ (FC0-U71)SecurityMedium

A user receives an email with an urgent warning about their bank account being compromised and instructing them to click a link to verify their details immediately. The email appears to be from their bank but contains a generic greeting and a suspicious-looking URL when hovered over. What type of social engineering attack is this?

  1. AVishing
  2. BTailgating
  3. CShoulder Surfing
  4. DPhishing
Show answer & explanation

Correct answer: D. Phishing

Phishing is a social engineering attack that uses fraudulent emails, messages, or websites to trick individuals into revealing sensitive information, such as usernames, passwords, and credit card details. The scenario describes a classic phishing attempt using a fake bank email with a suspicious link.

Why the other options are wrong

  • A. Vishing is phishing conducted over the phone, not via email.
  • B. Tailgating is gaining unauthorized access by following someone through a secured entry point.
  • C. Shoulder surfing is observing someone's screen or keyboard to steal information, typically in person.

Phishing

A social engineering technique that uses deceptive electronic communications (e.g., email) to trick individuals into revealing sensitive information or performing actions.

  • Often impersonates trusted entities (banks, companies).
  • Aims to steal credentials, financial data, or install malware.
  • Relies on urgency, fear, or curiosity to manipulate victims.

Memory trick: Social engineers trick you with human nature.

More Security questions