nerdexam
EC-Council

312-50V11 · Question #88

In this attack, a victim receives an e-mail claiming from PayPal stating that their account has been disabled and confirmation is required before activation. The attackers then scam to collect not…

The correct answer is D. Antivirus, anti-spyware, and firewall software can very easily detect these type of attacks. This question describes a phishing attack mimicking PayPal and asks which listed statement is incorrect. The incorrect statement falsely claims that security software can easily detect phishing attacks.

Social Engineering

Question

In this attack, a victim receives an e-mail claiming from PayPal stating that their account has been disabled and confirmation is required before activation. The attackers then scam to collect not one but two credit card numbers, ATM PIN number and other personal details. Ignorant users usually fall prey to this scam. Which of the following statement is incorrect related to this attack?

Options

  • ADo not reply to email messages or popup ads asking for personal or financial information
  • BDo not trust telephone numbers in e-mails or popup ads
  • CReview credit card and bank account statements regularly
  • DAntivirus, anti-spyware, and firewall software can very easily detect these type of attacks
  • EDo not send credit card numbers, and personal or financial information via e-mail

How the community answered

(35 responses)
  • B
    3% (1)
  • C
    6% (2)
  • D
    89% (31)
  • E
    3% (1)

Why each option

This question describes a phishing attack mimicking PayPal and asks which listed statement is incorrect. The incorrect statement falsely claims that security software can easily detect phishing attacks.

ADo not reply to email messages or popup ads asking for personal or financial information

This is a correct defensive recommendation - users should never reply to unsolicited emails or popups requesting personal or financial information, making it a valid protective measure and not an incorrect statement.

BDo not trust telephone numbers in e-mails or popup ads

This is a correct defensive recommendation - phone numbers embedded in phishing emails often connect to fraudulent call centers run by attackers, so verifying contact details through official channels is legitimate advice.

CReview credit card and bank account statements regularly

This is a correct defensive recommendation - regularly reviewing bank and credit card statements allows victims to detect unauthorized charges early, which is a recognized best practice against financial phishing.

DAntivirus, anti-spyware, and firewall software can very easily detect these type of attacksCorrect

Phishing attacks exploit human psychology rather than technical vulnerabilities, making them extremely difficult for antivirus, anti-spyware, and firewall software to reliably detect. These tools scan for malicious code or known malware signatures, but a phishing email contains no malware - it simply deceives users into voluntarily submitting sensitive information. Security software cannot easily distinguish a fraudulent PayPal email from a legitimate one based on deceptive content alone.

EDo not send credit card numbers, and personal or financial information via e-mail

This is a correct defensive recommendation - legitimate organizations like PayPal or banks never request sensitive financial credentials via email, so advising users not to transmit such data over email is accurate.

Concept tested: Phishing attack defenses and detection limitations

Source: https://www.cisa.gov/secure-our-world/phishing

Topics

#phishing#social engineering attacks#email scams#countermeasures

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice