CompTIA Tech+ (FC0-U71)SecurityMedium

A user receives an email with an urgent warning about their bank account being compromised. The email contains a link that, when clicked, leads to a website that looks identical to their bank's login page. The user is prompted to enter their credentials. This scenario is a classic example of which social engineering attack?

  1. APhishing
  2. BBaiting
  3. CQuid pro quo
  4. DPretexting
Show answer & explanation

Correct answer: A. Phishing

Phishing is a type of social engineering attack where an attacker attempts to trick individuals into divulging sensitive information, such as usernames, passwords, and credit card details, by masquerading as a trustworthy entity in an electronic communication.

Why the other options are wrong

  • B. Baiting involves offering something enticing (like free software) to lure victims into a trap.
  • C. Quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password').
  • D. Pretexting involves creating a fabricated scenario (pretext) to gain information from a target.

Phishing

A social engineering attack where attackers send fraudulent communications that appear to come from a reputable source, often via email, to trick recipients into revealing sensitive information or clicking malicious links.

  • Uses deception to gain trust.
  • Often mimics legitimate entities (banks, companies).
  • Aims to steal credentials or install malware.

Memory trick: Social engineering: Tricking people, not tech.

More Security questions