nerdexam
LPI

303-300 · Question #102

What is phishing?

The correct answer is D. A type of social engineering attack. Phishing is a social engineering attack (D) because it manipulates people psychologically - typically through deceptive emails, messages, or fake websites - to trick victims into revealing sensitive information like passwords or credit card numbers. It exploits human trust, not…

Threat Detection and Incident Response

Question

What is phishing?

Options

  • AA type of virus
  • BA type of malware that disguises itself as legitimate software
  • CA type of denial-of-service attack
  • DA type of social engineering attack

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    4% (2)
  • D
    95% (52)

Explanation

Phishing is a social engineering attack (D) because it manipulates people psychologically - typically through deceptive emails, messages, or fake websites - to trick victims into revealing sensitive information like passwords or credit card numbers. It exploits human trust, not technical vulnerabilities in software.

Why the distractors are wrong:

  • A (virus): A virus is self-replicating malicious code that spreads by attaching to files - phishing involves no such code.
  • B (malware disguised as legitimate software): That describes a Trojan horse, not phishing.
  • C (denial-of-service): DoS attacks flood systems to make them unavailable - phishing targets people, not infrastructure.

Memory tip: Think of the fishing analogy - a phisher casts a bait (fake email/site) hoping a person bites and hands over credentials. The "ph" spelling is a hacker culture convention. If the attack tricks a human rather than exploiting a system, it's social engineering.

Topics

#Social Engineering#Phishing#Threat Detection#User Security

Community Discussion

No community discussion yet for this question.

Full 303-300 Practice