nerdexam
EC-Council

312-50V12 · Question #305

Stephen, an attacker, targeted the industrial control systems of an organization. He generated a fraudulent email with a malicious attachment and sent it to employees of the target organization. An…

The correct answer is D. Spear-phishing attack. The attack involved Stephen sending a targeted, fraudulent email with a malicious attachment to specific employees of an organization, leading to malware injection and damage to industrial systems.

Submitted by chiamaka_o· Mar 4, 2026System Hacking Phases and Attack Techniques

Question

Stephen, an attacker, targeted the industrial control systems of an organization. He generated a fraudulent email with a malicious attachment and sent it to employees of the target organization. An employee who manages the sales software of the operational plant opened the fraudulent email and clicked on the malicious attachment. This resulted in the malicious attachment being downloaded and malware being injected into the sales software maintained in the victim's system. Further, the malware propagated itself to other networked systems, finally damaging the industrial automation components. What is the attack technique used by Stephen to damage the industrial systems?

Options

  • AHMI-based attack
  • BSMishing attack
  • CReconnaissance attack
  • DSpear-phishing attack

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    5% (2)
  • C
    14% (5)
  • D
    76% (28)

Why each option

The attack involved Stephen sending a targeted, fraudulent email with a malicious attachment to specific employees of an organization, leading to malware injection and damage to industrial systems.

AHMI-based attack

An HMI-based attack involves exploiting vulnerabilities in Human-Machine Interfaces used to control industrial systems directly, which is distinct from an email-based initial compromise.

BSMishing attack

SMishing refers to phishing attacks conducted specifically via SMS text messages, while the scenario clearly states that a 'fraudulent email' was used.

CReconnaissance attack

Reconnaissance is the initial phase of gathering information about a target before an attack, not the execution phase involving sending malicious emails and injecting malware.

DSpear-phishing attackCorrect

Spear phishing is a highly targeted social engineering attack where an attacker sends fraudulent emails to specific individuals or organizations, often leveraging personalized information to trick them. The scenario describes Stephen sending a malicious email with an attachment to employees of the target organization, specifically one who manages sales software, which resulted in malware injection and system damage, perfectly aligning with the characteristics of a spear-phishing attack.

Concept tested: Identifying spear-phishing attacks in industrial control systems

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/phishing-scams-how-to-recognize-them-and-stay-safe?view=o365-worldwide

Topics

#spear-phishing#social engineering#malware delivery#ICS security

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice