100-140 Question 344
Single answerA user contacts the IT support team reporting that they received an email from their bank requesting immediate action to verify their account by clicking a link. Upon inspection, the IT support technician notices the email contains spelling errors, an unfamiliar sender address, and a sense of urgency. What type of threat is most likely being described in this scenario?
- A
Phishing
- B
Malware
- C
Spam
- D
Spoofing
Show answer and explanation
Correct answer: A
Explanation
The described scenario is an example of phishing. Phishing attacks often use urgency, suspicious sender details, and requests for sensitive information to trick users. While spoofing might be involved in this case (e.g., faking the sender’s email address), phishing accurately describes the threat's primary objective.
- A. Correct.
Phishing is a type of social engineering attack that tricks users into providing sensitive information by pretending to be a legitimate entity, such as a bank. The sense of urgency and suspicious details in the email are typical signs of phishing.
- B. Incorrect.
Malware refers to malicious software designed to harm a system, such as viruses or ransomware. While malware can be delivered via email, the scenario does not describe any software being installed or executed.
- C. Incorrect.
Spam refers to unsolicited bulk messages, often promotional. While phishing emails can sometimes appear as spam, this specific email is attempting to deceive the user into providing sensitive information, which is a hallmark of phishing.
- D. Incorrect.
Spoofing involves falsifying the identity of a sender to appear as a trusted source, often used in conjunction with phishing. However, spoofing is not the main focus of this scenario, as the primary goal is to trick the user into sharing sensitive information.