CompTIA Tech+ (FC0-U71)SecurityMedium
A user receives an email with an urgent warning about their bank account being compromised and instructing them to click a link to verify their details immediately. The email appears to be from their bank but contains a generic greeting and a suspicious-looking URL when hovered over. What type of social engineering attack is this?
- AVishing
- BTailgating
- CShoulder Surfing
- DPhishing
Show answer & explanationAnswer & explanation
Correct answer: D. Phishing
Phishing is a social engineering attack that uses fraudulent emails, messages, or websites to trick individuals into revealing sensitive information, such as usernames, passwords, and credit card details. The scenario describes a classic phishing attempt using a fake bank email with a suspicious link.
Why the other options are wrong
- A. Vishing is phishing conducted over the phone, not via email.
- B. Tailgating is gaining unauthorized access by following someone through a secured entry point.
- C. Shoulder surfing is observing someone's screen or keyboard to steal information, typically in person.
Phishing
A social engineering technique that uses deceptive electronic communications (e.g., email) to trick individuals into revealing sensitive information or performing actions.
- Often impersonates trusted entities (banks, companies).
- Aims to steal credentials, financial data, or install malware.
- Relies on urgency, fear, or curiosity to manipulate victims.
Memory trick: Social engineers trick you with human nature.