100-140 Question 343
Select 2An employee receives an email that appears to be from their company's IT department, requesting they click a link to reset their password. Upon closer inspection, the email contains grammatical errors, and the link redirects to a suspicious website. Which types of threats are most likely involved in this scenario?
- A
Phishing
- B
Malware
- C
Spoofing
- D
Spam
- E
Unauthorized access attempt
Show answer and explanation
Correct answers: A, C
Explanation
This scenario involves phishing and spoofing threats. The email is designed to deceive the user into clicking on a fraudulent link and providing sensitive information, which is a hallmark of phishing. Additionally, the email pretends to originate from the company's IT department, which constitutes spoofing. While related risks like unauthorized access could follow, phishing and spoofing are the immediate threats presented in this scenario.
- A. Correct.
Phishing is the correct answer because the email is attempting to trick the user into providing sensitive information (e.g., their password) by pretending to be a legitimate entity.
- B. Incorrect.
Malware is not correct in this scenario as there is no indication that the email contains a malicious attachment or software designed to harm the system.
- C. Correct.
Spoofing is correct because the email appears to come from the company's IT department, which is likely forged to mislead the recipient.
- D. Incorrect.
Spam is not correct because, while the email could be considered unsolicited, the primary intent is to deceive the user rather than just sending bulk unsolicited messages.
- E. Incorrect.
Unauthorized access attempt is not directly correct in this case because the email itself does not constitute an access attempt, but rather a phishing attack to gather the credentials needed for such an attempt.