nerdexam
CompTIA

220-1102 · Question #632

A user receives an email from what appears to be a trusted, known insider who is requesting confidential banking information. After the user further inspects the email, the user notices that one…

The correct answer is D. Impersonation. The scenario describes a malicious actor sending an email that mimics a trusted insider but has a subtle email address error, indicating an attempt to deceive the recipient into believing they are communicating with the legitimate person. This is a classic example of…

Security

Question

A user receives an email from what appears to be a trusted, known insider who is requesting confidential banking information. After the user further inspects the email, the user notices that one character in the email address is incorrect. Which of the following is being attempted?

Options

  • AEvil twin
  • BInsider threat
  • CZero-day attack
  • DImpersonation

How the community answered

(21 responses)
  • B
    5% (1)
  • C
    5% (1)
  • D
    90% (19)

Why each option

The scenario describes a malicious actor sending an email that mimics a trusted insider but has a subtle email address error, indicating an attempt to deceive the recipient into believing they are communicating with the legitimate person. This is a classic example of impersonation.

AEvil twin

An evil twin attack involves a rogue wireless access point masquerading as a legitimate one to intercept traffic.

BInsider threat

An insider threat involves a current or former employee, contractor, or business partner with authorized access who intentionally or unintentionally misuses that access.

CZero-day attack

A zero-day attack exploits a previously unknown vulnerability in software or hardware for which no patch or fix exists.

DImpersonationCorrect

Impersonation is a social engineering technique where an attacker pretends to be a legitimate person or entity to gain unauthorized access or information. The incorrect character in the email address is a common tactic used to mimic a known sender, thereby tricking the recipient into trusting the fraudulent communication.

Concept tested: Impersonation in social engineering

Source: https://learn.microsoft.com/en-us/purview/email-protection-spoofing

Topics

#Impersonation#Social Engineering#Email Security#Phishing

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice