Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsMedium
A user receives an email that appears to be from their bank, asking them to click a link to verify their account details due to 'unusual activity'. The email contains the bank's logo and a convincing layout, but the link points to a slightly misspelled domain. Which type of common security threat is this?
- APhishing
- BDenial of Service (DoS)
- CRootkit
- DBuffer Overflow
Show answer & explanationAnswer & explanation
Correct answer: A. Phishing
This scenario describes a classic phishing attempt. The attacker uses social engineering (a deceptive email) to trick the user into revealing sensitive information by impersonating a trusted entity and directing them to a fake website.
Why the other options are wrong
- B. DoS attacks aim to make a service unavailable and do not involve deceptive emails for credential harvesting.
- C. A rootkit is a type of malware designed to gain root-level access and hide its presence, not an email-based social engineering attack.
- D. A buffer overflow is a programming error that can lead to system crashes or arbitrary code execution, not a social engineering tactic.
Phishing
A social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (like usernames, passwords, credit card details) by impersonating a trustworthy entity in electronic communication.
- Uses deception and impersonation
- Often delivered via email or text (smishing)
- Aims to steal credentials or install malware
- Indicators include suspicious links, generic greetings, urgent tone
Memory trick: Social 'S'chemes: Phishing, Pretexting, Tailgating.