Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A large corporation is developing a new security awareness training program for its employees. One of the modules focuses on teaching employees to identify suspicious emails that attempt to trick them into revealing sensitive information, such as login credentials or financial data, by impersonating trusted entities. What type of attack is this module primarily aiming to combat?

  1. ADenial of Service (DoS)
  2. BMan-in-the-Middle (MitM)
  3. CMalware Infection
  4. DPhishing
Show answer & explanation

Correct answer: D. Phishing

Phishing is a social engineering attack that uses fraudulent communications, typically email, to trick recipients into revealing sensitive information or deploying malicious software. The description of 'suspicious emails' impersonating 'trusted entities' to 'reveal sensitive information' perfectly defines phishing.

Why the other options are wrong

  • A. DoS attacks aim to make services unavailable, not to trick users into revealing data.
  • B. MitM intercepts communication, not primarily a trick via email.
  • C. Malware infection is the result of some attacks, but phishing is the method described to achieve it (or data theft).

Phishing

A type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information, such as usernames, passwords, and credit card details, by masquerading as a trustworthy entity in electronic communication.

  • Often uses email, but can also be via SMS (smishing) or voice (vishing).
  • Relies on impersonation and urgency/fear tactics.
  • Aims to steal credentials, install malware, or commit fraud.

Memory trick: Social Engineering: Phishing, Pretexting, Baiting, Quid Pro Quo, Tailgating

More Security Principles questions