GSLC · Question #441
Which of the following types of attacks entices a user to disclose personal information such as social security number, bank account details, or credit card number?
The correct answer is B. Phishing. Phishing is a social engineering attack that tricks users into voluntarily revealing sensitive personal or financial information, typically through deceptive emails or fake websites.
Question
Which of the following types of attacks entices a user to disclose personal information such as social security number, bank account details, or credit card number?
Options
- ASpoofing
- BPhishing
- CPassword guessing attack
- DReplay attack
How the community answered
(56 responses)- A5% (3)
- B91% (51)
- C2% (1)
- D2% (1)
Why each option
Phishing is a social engineering attack that tricks users into voluntarily revealing sensitive personal or financial information, typically through deceptive emails or fake websites.
Spoofing involves forging the identity of a sender or system (e.g., IP or email spoofing) to disguise origin, but does not inherently solicit personal information from the victim.
Phishing attacks specifically target users by impersonating trusted entities to lure them into submitting sensitive data such as Social Security numbers, bank account credentials, or credit card numbers. The attack relies on deception and urgency rather than technical exploitation. It is the defining characteristic of phishing that the victim willingly provides the information.
A password guessing attack involves systematically attempting credential combinations against an authentication system, not enticing users to voluntarily disclose information.
A replay attack captures legitimate authentication or data packets and retransmits them to gain unauthorized access, not to trick users into revealing personal details.
Concept tested: Phishing social engineering attack identification
Source: https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/phishing
Topics
Community Discussion
No community discussion yet for this question.