100-160 Question 24
Single answerAn employee at a company receives an email that appears to be from their IT department, requesting them to click a link and log in to verify their credentials. The email has a sense of urgency, stating that failure to do so will result in account deactivation. What type of cyberattack does this scenario describe?
- A
Phishing
- B
Vishing
- C
Spear phishing
- D
Tailgating
Show answer and explanation
Correct answer: A
Explanation
The described scenario is a phishing attack, where the attacker sends a generic email designed to trick individuals into clicking on a malicious link and entering sensitive information. This type of attack relies on creating a sense of urgency to manipulate the victim.
- A. Correct.
Phishing is a type of social engineering attack that uses emails or messages to trick individuals into revealing sensitive information or performing actions like clicking malicious links. This scenario matches the definition of phishing.
- B. Incorrect.
Vishing involves voice-based attacks, such as phone calls, to deceive individuals into sharing sensitive information. This attack does not involve a phone call, so vishing is incorrect.
- C. Incorrect.
Spear phishing is a more targeted form of phishing, typically aimed at a specific individual or organization. While this example could resemble spear phishing, the scenario does not specify that the email was tailored to the employee or targeted at them directly.
- D. Incorrect.
Tailgating is a physical security attack where an unauthorized person follows an authorized individual into a restricted area. This scenario does not involve physical access, so tailgating is incorrect.