nerdexam
CompTIA

CAS-003 · Question #593

Which of the following attacks can be used to exploit a vulnerability that was created by untrained users?

The correct answer is A. A spear-phishing email with a file attachment. Spear-phishing emails with malicious file attachments directly exploit the vulnerability created by untrained users who cannot recognize social engineering or suspicious content.

Enterprise Security Operations

Question

Which of the following attacks can be used to exploit a vulnerability that was created by untrained users?

Options

  • AA spear-phishing email with a file attachment
  • BA DoS using IoT devices
  • CAn evil twin wireless access point
  • DA domain hijacking of a bank website

How the community answered

(51 responses)
  • A
    88% (45)
  • B
    4% (2)
  • C
    6% (3)
  • D
    2% (1)

Why each option

Spear-phishing emails with malicious file attachments directly exploit the vulnerability created by untrained users who cannot recognize social engineering or suspicious content.

AA spear-phishing email with a file attachmentCorrect

Spear-phishing is a targeted social engineering attack that succeeds specifically because untrained users lack the awareness to identify deceptive sender identities, urgent or manipulative language, and malicious attachments. When an untrained user opens a malicious file, they trigger the attack vector that proper security awareness training is designed to prevent. This attack exploits human behavior - a vulnerability that is directly created and sustained by inadequate user training.

BA DoS using IoT devices

A DoS attack using IoT devices exploits misconfigured or unpatched device firmware and network infrastructure weaknesses, not the knowledge gap of individual end users.

CAn evil twin wireless access point

An evil twin access point is a network interception attack that can affect even security-aware users and relies on proximity and wireless infrastructure vulnerabilities rather than user training gaps.

DA domain hijacking of a bank website

Domain hijacking exploits weaknesses in domain registrar account security or DNS infrastructure and is a technical attack that is not dependent on end-user training levels.

Concept tested: Social engineering attacks exploiting untrained user behavior

Source: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one

Topics

#spear-phishing#social engineering#user awareness training#phishing vectors

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice