100-160 Question 16
Select 2A user within your organization reports receiving an email claiming to be from your IT department, requesting they reset their account password by clicking a link. The email looks suspicious, and upon investigation, you confirm it is a phishing attempt. Which common threats or vulnerabilities does this scenario illustrate?
- A
Social engineering
- B
Weak password policy
- C
Phishing
- D
Privilege escalation
- E
Malware infection
Show answer and explanation
Correct answers: A, C
Explanation
The described scenario highlights a phishing attack, which is a specific type of social engineering tactic. Attackers use such emails to trick users into providing sensitive information or performing actions that compromise security. Understanding and identifying these threats are crucial for mitigating risks in cybersecurity.
- A. Correct.
Social engineering is a tactic used by attackers to manipulate individuals into divulging confidential information or performing actions, such as clicking a malicious link. This is evident in the scenario where the attacker attempts to trick the user into resetting their password via a phishing email.
- B. Incorrect.
Weak password policy refers to insufficient security measures for password creation, such as not enforcing complexity or regular updates. While weak passwords can lead to security risks, they are not directly relevant to the phishing attempt described in the scenario.
- C. Correct.
Phishing is a type of cyberattack where attackers impersonate legitimate entities to trick individuals into sharing sensitive information or downloading malicious content. This is clearly demonstrated in the situation where an email is sent to lure the user into resetting their password.
- D. Incorrect.
Privilege escalation refers to attackers gaining higher access levels within a system than they are supposed to have. This is not relevant to the described phishing email.
- E. Incorrect.
Malware infection involves malicious software being installed on a device, which does not occur in the described phishing scenario unless the link in the email led to malware (not stated in the scenario).