PT0-003 · Question #255
A penetration tester is assessing the overall preparedness of a client's staff for text-message- based attacks. Which of the following most accurately describes the attack technique the tester is…
The correct answer is D. Smishing. Smishing (D) is correct because it refers specifically to phishing attacks conducted via SMS/text messages, making it the precise term for text-message-based social engineering - exactly what the penetration tester is simulating against staff. Whaling (A) is wrong because it…
Question
A penetration tester is assessing the overall preparedness of a client's staff for text-message- based attacks. Which of the following most accurately describes the attack technique the tester is assessing?
Options
- AWhaling
- BVishing
- CWardriving
- DSmishing
How the community answered
(58 responses)- A2% (1)
- B5% (3)
- C3% (2)
- D90% (52)
Explanation
Smishing (D) is correct because it refers specifically to phishing attacks conducted via SMS/text messages, making it the precise term for text-message-based social engineering - exactly what the penetration tester is simulating against staff.
- Whaling (A) is wrong because it describes phishing attacks that specifically target high-profile executives (C-suite), not a delivery method like text messages.
- Vishing (B) is wrong because it refers to phishing conducted over voice calls (phone calls), not text messages.
- Wardriving (C) is wrong because it involves driving around with a device to map or exploit wireless networks, which has nothing to do with social engineering via messages.
Memory Tip: Use the first letters to distinguish the "ishing" family - Smishing = SMS, Vishing = Voice, Phishing = email. Whaling is the odd one out as it describes a target type (big fish = whale = executive), not a delivery channel.
Topics
Community Discussion
No community discussion yet for this question.