nerdexam
CompTIA

SY0-501 · Question #12

Hotspot Question Select the appropriate attack from each drop down list to label the corresponding illustrated attack Instructions: Attacks may only be used once, and will disappear from drop down…

This hotspot simulation tests the ability to identify and correctly label common network/cybersecurity attack types based on illustrated diagrams. Each diagram depicts a unique attack scenario that must be matched to the correct attack name from a dropdown list.

Submitted by manish99· Mar 4, 2026Messaging Security

Question

Hotspot Question Select the appropriate attack from each drop down list to label the corresponding illustrated attack Instructions: Attacks may only be used once, and will disappear from drop down list if selected. When you have completed the simulation, please select the Done button to submit. Answer:

Exhibits

SY0-501 question #12 exhibit 1
SY0-501 question #12 exhibit 2

Answer Area

  • Attacker gains confidential company information / Targeted CEO and board members
    SPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
  • Attacker posts link to fake AV software / Multiple social networks / Broad set of victims
    SPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
  • Attacker collecting credit card details / Phone-based victim
    SPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
  • Attacker mass-mails product information to parties that have already opted out of receiving advertisements / Broad set of recipients
    SPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING
  • Attacker redirects name resolution entries from legitimate site to fraudulent site / Victims
    SPEAR PUSHINGHOAXVISHINGPHISHINGPHARMING

Explanation

This hotspot simulation tests the ability to identify and correctly label common network/cybersecurity attack types based on illustrated diagrams. Each diagram depicts a unique attack scenario that must be matched to the correct attack name from a dropdown list.

Approach. To correctly answer this question, analyze each illustrated diagram carefully for key indicators: Phishing attacks show deceptive emails/websites mimicking legitimate entities; Man-in-the-Middle (MitM) attacks show an interceptor positioned between two communicating parties; DoS/DDoS attacks show overwhelming traffic flooding a target; SQL Injection shows malicious input being entered into a database-connected form; ARP Poisoning shows false MAC-to-IP mappings being sent to hosts on a LAN; Replay attacks show captured legitimate credentials being retransmitted; and Social Engineering shows manipulation of human behavior rather than technical exploitation. Match each visual clue - such as arrows showing data flow, attacker positioning, or system components - to the attack that best fits the scenario depicted.

Concept tested. Identification and classification of common cybersecurity attack types including but not limited to: Phishing, Man-in-the-Middle, DDoS, SQL Injection, ARP Poisoning, Replay Attack, and Social Engineering, based on visual scenario recognition.

Reference. CompTIA Security+ SY0-701 Exam Objectives: Domain 2.0 – Threats, Vulnerabilities, and Mitigations; NIST SP 800-61 Computer Security Incident Handling Guide

Topics

#social engineering#phishing#vishing#pharming

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice