nerdexam
CompTIA

220-801 · Question #795

A user received an email from their bank asking them to login and verify their personal information. The user complies and fills in the requested information. Days later the user notices their…

The correct answer is B. Phishing. The scenario describes a phishing attack where a fraudulent email mimicked a bank to steal credentials and drain the user's account.

Networking

Question

A user received an email from their bank asking them to login and verify their personal information. The user complies and fills in the requested information. Days later the user notices their checking account is empty. This is a result of which of the following?

Options

  • ASpam
  • BPhishing
  • CAdware
  • DA Trojan

How the community answered

(61 responses)
  • A
    2% (1)
  • B
    89% (54)
  • C
    3% (2)
  • D
    7% (4)

Why each option

The scenario describes a phishing attack where a fraudulent email mimicked a bank to steal credentials and drain the user's account.

ASpam

Spam is unsolicited bulk email used for advertising or distribution and is not specifically designed to harvest credentials or access financial accounts.

BPhishingCorrect

Phishing is a social engineering attack where an attacker impersonates a trusted entity such as a bank via email to trick users into submitting sensitive credentials. The fraudulent site harvests login and personal data, giving attackers direct access to financial accounts, which explains the emptied checking account.

CAdware

Adware is software that automatically displays or downloads advertising material and does not involve credential harvesting via fake login pages.

DA Trojan

A Trojan is malware disguised as legitimate software installed on a device, but this scenario involves no software installation - only deceptive credential collection via a fake web form.

Concept tested: Phishing social engineering attack identification

Source: https://www.cisa.gov/topics/cybersecurity-best-practices/phishing

Topics

#phishing#social engineering#email security#account compromise

Community Discussion

No community discussion yet for this question.

Full 220-801 Practice