1D0-610 · Question #58
Which type of attack is a form of social engineering in which an attacker attempts to steal personal or confidential information by sending e-mail that lures unsuspecting victims to log in to an…
The correct answer is B. Phishing. Phishing (B) is correct because it describes the exact technique of crafting deceptive emails that direct victims to fake but convincing websites to harvest credentials or sensitive data - the defining characteristic is the email-as-lure combined with an impersonated site…
Question
Which type of attack is a form of social engineering in which an attacker attempts to steal personal or confidential information by sending e-mail that lures unsuspecting victims to log in to an authentic-looking but imposter Web site?
Options
- AReplay
- BPhishing
- CSpoofing
- DPharming
How the community answered
(22 responses)- A5% (1)
- B91% (20)
- D5% (1)
Explanation
Phishing (B) is correct because it describes the exact technique of crafting deceptive emails that direct victims to fake but convincing websites to harvest credentials or sensitive data - the defining characteristic is the email-as-lure combined with an impersonated site.
- Replay (A) is wrong - a replay attack intercepts and retransmits valid network communications to impersonate a user, with no fake website or email involved.
- Spoofing (C) is wrong - spoofing involves forging an identity (IP, email sender, DNS), which is a component of phishing infrastructure but not the full attack described.
- Pharming (D) is close but wrong - pharming also redirects users to fake sites, but does so by corrupting DNS or hosts files, without requiring the victim to click an email link.
Memory tip: Think "phishing = fishing with email bait" - the attacker casts a deceptive email hoping a victim takes the hook and swims to a fake site.
Topics
Community Discussion
No community discussion yet for this question.