CompTIA Tech+ (FC0-U71)SecurityMedium
A user receives an email with an urgent warning about their bank account being compromised. The email contains a link that, when clicked, leads to a website that looks identical to their bank's login page. The user is prompted to enter their credentials. This scenario is a classic example of which social engineering attack?
- APhishing
- BBaiting
- CQuid pro quo
- DPretexting
Show answer & explanationAnswer & explanation
Correct answer: A. Phishing
Phishing is a type of social engineering attack where an attacker attempts to trick individuals into divulging sensitive information, such as usernames, passwords, and credit card details, by masquerading as a trustworthy entity in an electronic communication.
Why the other options are wrong
- B. Baiting involves offering something enticing (like free software) to lure victims into a trap.
- C. Quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password').
- D. Pretexting involves creating a fabricated scenario (pretext) to gain information from a target.
Phishing
A social engineering attack where attackers send fraudulent communications that appear to come from a reputable source, often via email, to trick recipients into revealing sensitive information or clicking malicious links.
- Uses deception to gain trust.
- Often mimics legitimate entities (banks, companies).
- Aims to steal credentials or install malware.
Memory trick: Social engineering: Tricking people, not tech.