nerdexam
CIW

1D0-61C · Question #38

Which type of attack is a form of social engineering in which an attacker attempts to steal personal or confidential information by sending e-mail that lures unsuspecting victims to log in to an…

The correct answer is B. Phishing. Phishing (B) is correct because it precisely describes the technique of crafting deceptive emails that trick victims into entering credentials on fraudulent lookalike websites - the defining combination of email lure + imposter site is the hallmark of phishing. A (Replay): A…

Network Security

Question

Which type of attack is a form of social engineering in which an attacker attempts to steal personal or confidential information by sending e-mail that lures unsuspecting victims to log in to an authentic-looking but imposter Web site?

Options

  • AReplay
  • BPhishing
  • CSpoofing
  • DPharming

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    94% (48)
  • D
    4% (2)

Explanation

Phishing (B) is correct because it precisely describes the technique of crafting deceptive emails that trick victims into entering credentials on fraudulent lookalike websites - the defining combination of email lure + imposter site is the hallmark of phishing.

  • A (Replay): A replay attack intercepts and retransmits valid network data (like authentication tokens) to impersonate a user - no fake website or email involved.
  • C (Spoofing): Spoofing is falsifying an identity (IP address, email sender, DNS entry) but doesn't necessarily involve luring victims to a fake site for credential theft.
  • D (Pharming): Pharming is close - it also redirects users to fake sites - but does so by poisoning DNS or host files, not through email. No lure is needed; victims are redirected automatically.

Memory tip: Think "phishing = fishing with email bait." The attacker casts an email hook hoping a victim bites by clicking and logging in. Pharming is the "farm" that silently redirects everyone without needing a hook.

Topics

#Phishing#Social Engineering#Email Security#Credential Theft

Community Discussion

No community discussion yet for this question.

Full 1D0-61C Practice