nerdexam
CompTIA

SY0-301 · Question #235

A security administrator notices large amounts of traffic within the network heading out to an external website. The website seems to be a fake bank site with a phone number that when called, asks…

The correct answer is B. Phishing. Phishing is an attack that uses deceptive messages containing fraudulent links to direct victims to fake websites designed to harvest sensitive information.

Threats, vulnerabilities, and mitigations

Question

A security administrator notices large amounts of traffic within the network heading out to an external website. The website seems to be a fake bank site with a phone number that when called, asks for sensitive information. After further investigation, the security administrator notices that a fake link was sent to several users. This is an example of which of the following attacks?

Options

  • AVishing
  • BPhishing
  • CWhaling
  • DSPAM
  • ESPIM

How the community answered

(46 responses)
  • B
    93% (43)
  • D
    4% (2)
  • E
    2% (1)

Why each option

Phishing is an attack that uses deceptive messages containing fraudulent links to direct victims to fake websites designed to harvest sensitive information.

AVishing

Vishing (voice phishing) uses telephone calls as the primary attack vector to deceive victims, not email or message-based links to fake websites.

BPhishingCorrect

This attack matches the definition of phishing precisely - a fake link was distributed to multiple users via a message, directing them to a spoofed bank website. The fake site included a phone number soliciting sensitive information, which is a credential harvesting technique commonly paired with phishing campaigns.

CWhaling

Whaling is a form of spear phishing that specifically targets high-profile executives or senior leadership, not general employee populations.

DSPAM

SPAM refers to unsolicited bulk messaging and is not inherently a targeted attack designed to harvest credentials via fake sites.

ESPIM

SPIM (Spam over Instant Messaging) refers to unsolicited messages sent through instant messaging platforms, not a targeted credential-harvesting campaign using fake websites.

Concept tested: Identifying phishing attacks and social engineering vectors

Source: https://csrc.nist.gov/glossary/term/phishing

Topics

#phishing#social engineering#email threats#vishing

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice