nerdexam
Cisco

200-201 · Question #371

An employee received an email from a colleague's address asking for the password for the domain controller. The employee noticed a missing letter within the sender's address. What does this incident…

The correct answer is C. social engineering. The incident describes a social engineering attack where an attacker manipulates an employee to divulge sensitive information, leveraging a slightly altered sender address to appear legitimate.

Submitted by packet_pusher· Mar 6, 2026Security Concepts

Question

An employee received an email from a colleague's address asking for the password for the domain controller. The employee noticed a missing letter within the sender's address. What does this incident describe?

Options

  • Ainsider attack
  • Bshoulder surfing
  • Csocial engineering
  • Dbrute-force attack

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    89% (41)
  • D
    2% (1)

Why each option

The incident describes a social engineering attack where an attacker manipulates an employee to divulge sensitive information, leveraging a slightly altered sender address to appear legitimate.

Ainsider attack

An insider attack involves a current or former employee, contractor, or business partner who has authorized access and misuses it for malicious purposes.

Bshoulder surfing

Shoulder surfing is a direct observation technique where an attacker literally looks over a victim's shoulder to obtain sensitive information like PINs or passwords.

Csocial engineeringCorrect

Social engineering is a broad category of attacks that rely on human psychological manipulation to trick users into performing actions or divulging confidential information, such as giving up a password. In this scenario, the attacker used a spoofed or similar-looking email address (typosquatting) to impersonate a colleague and solicit sensitive data, which is a classic social engineering tactic.

Dbrute-force attack

A brute-force attack involves systematically trying all possible combinations of characters to guess a password or encryption key, rather than tricking a user into providing it.

Concept tested: Social engineering attack identification

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/social-engineering?view=o365-worldwide

Topics

#social engineering#phishing#attack vectors

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice