nerdexam
EC-Council

312-50V13 · Question #142

In this attack, a victim receives an e-mail claiming from PayPal stating that their account has been disabled and confirmation is required before activation. The attackers then scam to collect not…

The correct answer is D. Antivirus, anti-spyware, and firewall software can very easily detect these type of attacks. The described scenario is a phishing attack, which is a social engineering technique designed to trick users into revealing sensitive information by impersonating a trustworthy entity.

Submitted by packet_pusher· Mar 6, 2026Social Engineering

Question

In this attack, a victim receives an e-mail claiming from PayPal stating that their account has been disabled and confirmation is required before activation. The attackers then scam to collect not one but two credit card numbers, ATM PIN number and other personal details. Ignorant users usually fall prey to this scam. Which of the following statement is incorrect related to this attack?

Options

  • ADo not reply to email messages or popup ads asking for personal or financial information
  • BDo not trust telephone numbers in e-mails or popup ads
  • CReview credit card and bank account statements regularly
  • DAntivirus, anti-spyware, and firewall software can very easily detect these type of attacks
  • EDo not send credit card numbers, and personal or financial information via e-mail

How the community answered

(28 responses)
  • A
    14% (4)
  • B
    4% (1)
  • C
    7% (2)
  • D
    71% (20)
  • E
    4% (1)

Why each option

The described scenario is a phishing attack, which is a social engineering technique designed to trick users into revealing sensitive information by impersonating a trustworthy entity.

ADo not reply to email messages or popup ads asking for personal or financial information

Not replying to suspicious emails or pop-ups asking for personal information is a correct and essential countermeasure against phishing.

BDo not trust telephone numbers in e-mails or popup ads

Not trusting telephone numbers provided in suspicious emails or ads is a correct countermeasure, as attackers often provide fake contact information.

CReview credit card and bank account statements regularly

Regularly reviewing financial statements is a crucial post-compromise detection method to identify unauthorized activity resulting from a successful phishing attack.

DAntivirus, anti-spyware, and firewall software can very easily detect these type of attacksCorrect

Antivirus, anti-spyware, and firewall software are primarily designed to detect and prevent malware or control network traffic, not to 'very easily' detect social engineering attacks like phishing, which exploit human psychology and trust rather than technical vulnerabilities.

EDo not send credit card numbers, and personal or financial information via e-mail

Sending sensitive information via unencrypted email is inherently insecure and a correct behavior to avoid, especially in response to unsolicited requests.

Concept tested: Phishing attack characteristics and prevention

Source: https://www.cisa.gov/news-events/news/stop-think-connect-what-you-need-know-about-phishing

Topics

#phishing#social engineering#email security#security awareness

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice