SY0-501 · Question #12
Hotspot Question Select the appropriate attack from each drop down list to label the corresponding illustrated attack Instructions: Attacks may only be used once, and will disappear from drop down…
This hotspot simulation tests the ability to identify and correctly label common network/cybersecurity attack types based on illustrated diagrams. Each diagram depicts a unique attack scenario that must be matched to the correct attack name from a dropdown list.
Question
Exhibits
Answer Area
- Attacker gains confidential company information / Targeted CEO and board membersSPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
- Attacker posts link to fake AV software / Multiple social networks / Broad set of victimsSPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
- Attacker collecting credit card details / Phone-based victimSPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
- Attacker mass-mails product information to parties that have already opted out of receiving advertisements / Broad set of recipientsSPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
- Attacker redirects name resolution entries from legitimate site to fraudulent site / VictimsSPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
Explanation
This hotspot simulation tests the ability to identify and correctly label common network/cybersecurity attack types based on illustrated diagrams. Each diagram depicts a unique attack scenario that must be matched to the correct attack name from a dropdown list.
Approach. To correctly answer this question, analyze each illustrated diagram carefully for key indicators: Phishing attacks show deceptive emails/websites mimicking legitimate entities; Man-in-the-Middle (MitM) attacks show an interceptor positioned between two communicating parties; DoS/DDoS attacks show overwhelming traffic flooding a target; SQL Injection shows malicious input being entered into a database-connected form; ARP Poisoning shows false MAC-to-IP mappings being sent to hosts on a LAN; Replay attacks show captured legitimate credentials being retransmitted; and Social Engineering shows manipulation of human behavior rather than technical exploitation. Match each visual clue - such as arrows showing data flow, attacker positioning, or system components - to the attack that best fits the scenario depicted.
Concept tested. Identification and classification of common cybersecurity attack types including but not limited to: Phishing, Man-in-the-Middle, DDoS, SQL Injection, ARP Poisoning, Replay Attack, and Social Engineering, based on visual scenario recognition.
Reference. CompTIA Security+ SY0-701 Exam Objectives: Domain 2.0 – Threats, Vulnerabilities, and Mitigations; NIST SP 800-61 Computer Security Incident Handling Guide
Topics
Community Discussion
No community discussion yet for this question.

