SY0-301 · Question #235
A security administrator notices large amounts of traffic within the network heading out to an external website. The website seems to be a fake bank site with a phone number that when called, asks…
The correct answer is B. Phishing. Phishing is an attack that uses deceptive messages containing fraudulent links to direct victims to fake websites designed to harvest sensitive information.
Question
A security administrator notices large amounts of traffic within the network heading out to an external website. The website seems to be a fake bank site with a phone number that when called, asks for sensitive information. After further investigation, the security administrator notices that a fake link was sent to several users. This is an example of which of the following attacks?
Options
- AVishing
- BPhishing
- CWhaling
- DSPAM
- ESPIM
How the community answered
(46 responses)- B93% (43)
- D4% (2)
- E2% (1)
Why each option
Phishing is an attack that uses deceptive messages containing fraudulent links to direct victims to fake websites designed to harvest sensitive information.
Vishing (voice phishing) uses telephone calls as the primary attack vector to deceive victims, not email or message-based links to fake websites.
This attack matches the definition of phishing precisely - a fake link was distributed to multiple users via a message, directing them to a spoofed bank website. The fake site included a phone number soliciting sensitive information, which is a credential harvesting technique commonly paired with phishing campaigns.
Whaling is a form of spear phishing that specifically targets high-profile executives or senior leadership, not general employee populations.
SPAM refers to unsolicited bulk messaging and is not inherently a targeted attack designed to harvest credentials via fake sites.
SPIM (Spam over Instant Messaging) refers to unsolicited messages sent through instant messaging platforms, not a targeted credential-harvesting campaign using fake websites.
Concept tested: Identifying phishing attacks and social engineering vectors
Source: https://csrc.nist.gov/glossary/term/phishing
Topics
Community Discussion
No community discussion yet for this question.