nerdexam
Cisco

200-201 · Question #274

An employee received an email from a colleague's address asking for the password for the domain controller. The employee noticed a missing letter within the sender's address. What does this incident…

The correct answer is D. social engineering. This incident describes a social engineering attack, specifically phishing, where an attacker impersonates a trusted source with a subtly altered email address to trick a user into divulging sensitive information.

Submitted by tyler.j· Mar 6, 2026Security Concepts

Question

An employee received an email from a colleague's address asking for the password for the domain controller. The employee noticed a missing letter within the sender's address. What does this incident describe?

Options

  • Abrute-force attack
  • Binsider attack
  • Cshoulder surfing
  • Dsocial engineering

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    3% (1)
  • D
    89% (31)

Why each option

This incident describes a social engineering attack, specifically phishing, where an attacker impersonates a trusted source with a subtly altered email address to trick a user into divulging sensitive information.

Abrute-force attack

A brute-force attack involves systematically trying many passwords or passphrases in an attempt to guess correctly, which is a technical attack and not what is described by an email requesting credentials.

Binsider attack

An insider attack involves a current or former employee, contractor, or business partner with legitimate access maliciously exploiting that access. Here, the attack originates from an external party impersonating an insider, indicated by the altered sender's address.

Cshoulder surfing

Shoulder surfing is a physical attack where an attacker directly observes a person entering sensitive information, such as passwords, by looking over their shoulder.

Dsocial engineeringCorrect

This scenario is a classic example of a social engineering attack, specifically phishing. The attacker impersonates a trusted colleague using a slightly altered email address (typosquatting) and creates a sense of urgency or authority to trick the employee into divulging sensitive information like a password for the domain controller, leveraging human trust and manipulation.

Concept tested: Phishing and social engineering

Source: https://www.cisa.gov/news-events/news/what-social-engineering

Topics

#Insider threat#Social engineering#Phishing

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice