Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium

A user receives an email that appears to be from their bank, asking them to click a link to verify their account details due to 'unusual activity'. The email contains the bank's logo and a convincing layout, but the link points to a slightly misspelled domain. Which type of common security threat is this?

  1. APhishing
  2. BDenial of Service (DoS)
  3. CRootkit
  4. DBuffer Overflow
Show answer & explanation

Correct answer: A. Phishing

This scenario describes a classic phishing attempt. The attacker uses social engineering (a deceptive email) to trick the user into revealing sensitive information by impersonating a trusted entity and directing them to a fake website.

Why the other options are wrong

  • B. DoS attacks aim to make a service unavailable and do not involve deceptive emails for credential harvesting.
  • C. A rootkit is a type of malware designed to gain root-level access and hide its presence, not an email-based social engineering attack.
  • D. A buffer overflow is a programming error that can lead to system crashes or arbitrary code execution, not a social engineering tactic.

Phishing

A social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (like usernames, passwords, credit card details) by impersonating a trustworthy entity in electronic communication.

  • Uses deception and impersonation
  • Often delivered via email or text (smishing)
  • Aims to steal credentials or install malware
  • Indicators include suspicious links, generic greetings, urgent tone

Memory trick: Social 'S'chemes: Phishing, Pretexting, Tailgating.

More Security Fundamentals questions