exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 158 discussion

Actual exam question from CompTIA's SY0-501
Question #: 158
Topic #: 1
[All SY0-501 Questions]

An employee receives an email, which appears to be from the Chief Executive Officer (CEO), asking for a report of security credentials for all users.
Which of the following types of attack is MOST likely occurring?

  • A. Policy violation
  • B. Social engineering
  • C. Whaling
  • D. Spear phishing
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Schwartzden
Highly Voted 5 years, 7 months ago
It cant be whaling since it says it is coming from what appears to be the CEO. It cant be spear-phishing since it is only going to one employee and doesn't seem like this employee is high up in the food chain. I want to say this is social engineering since it is coming from someone high up asking for classified information and most likely it is with a sense of importance. A classic example of a social engineering attack
upvoted 13 times
Nathanf123
2 years, 8 months ago
Also the CEO is being impersonated, made me think of social engineering aswell.
upvoted 1 times
...
exiledwl
4 years, 4 months ago
Darill gibson book : Spear phishing is a targeted form of phishing. Instead of sending the email out to everyone indiscriminately, a spear phishing attack attempts to target specific groups of users, or even a single user. Spear phishing attacks may target employees within a company or customers of a company. As an example, an attacker might try to impersonate the CEO of an organization in an email
upvoted 10 times
sukhpal
3 years, 10 months ago
Agree with your point, but this can be phishing also, we can't ignore that too.
upvoted 1 times
...
...
...
ctux
Highly Voted 5 years, 6 months ago
Social engineering is the principle, spear phishing is the method of attack used. I think the right answer is D.
upvoted 8 times
eazy99
4 years, 5 months ago
I agree, Social engineering includes phishing, vishing, spear phishing, etc...
upvoted 1 times
...
...
TheUknownPirate
Most Recent 1 year, 6 months ago
The attack described in the question is an example of a social engineering attack. Social engineering attacks rely on manipulating individuals to disclose sensitive information or perform actions that they would not typically perform under normal circumstances. In this scenario, the attacker is impersonating the CEO of the company, which is a form of pretexting. The attacker is attempting to trick the employee into disclosing sensitive information, specifically security credentials for all users.
upvoted 1 times
...
SugaRay
3 years, 9 months ago
Keyword is CEO receiving this type of email - Spear Phishing
upvoted 1 times
...
Comicbookman
4 years, 3 months ago
From Kaspersky: Spear phishing is an email or electronic communications scam targeted towards a specific individual, organization or business. Although often intended to steal data for malicious purposes, cybercriminals may also intend to install malware on a targeted user’s computer.
upvoted 1 times
...
who__cares123456789___
4 years, 3 months ago
I see exactly why there is only 65% first time pass rate....some on here dont seem to know that SPEARFISHING is AIMED at a single person....ya know, like that single Halibut tou throw a spear at? JEEZ, answer is SPEARFISH, now move on!
upvoted 3 times
...
nickwen007
4 years, 3 months ago
As long as you see anything regarding email, think of phishing.
upvoted 1 times
...
MichaelLangdon
4 years, 4 months ago
How do ppl even pass the exam with questions like this???
upvoted 3 times
exiledwl
4 years, 4 months ago
I'm hoping their grading scale implements partial credit or full credit for being in the ballpark
upvoted 1 times
...
...
hardworker33
4 years, 8 months ago
There is multiple definitions of Spear phishing online. On the CompTia 2019 update, Exam SYO-501 book, it says "Spear phishing refers to a phishing scam where the attacker has some information that makes an individual target more likely to be fooled by the attack. The attacker might know the name of a document that the target is editing, for instance, and send a malicious copy, or the phishing email might show that the attacker knows the recipient's full name, job title, telephone number, or other details that help convince the target that the communication is genuine." So I can be an individual according to this definition, so I go with D.
upvoted 2 times
...
Crkvica
4 years, 9 months ago
D. Spear phishing, the target are all users...
upvoted 1 times
MTK777
4 years, 8 months ago
The target on "An employee" not all users!
upvoted 2 times
exiledwl
4 years, 4 months ago
Regardless spear phising can be specific to one user
upvoted 2 times
...
...
...
dinosan
4 years, 9 months ago
"Source: Get Certified Get Ahead - Darril Gibson." Spear phishing is a targeted form of phishing. Instead of sending the email out to everyone indiscriminately, a spear phishing attack attempts to target specific groups of users, or even a single user. Spear phishing attacks may target employees within a company or customers of a company. As an example, an attacker might try to impersonate the CEO of an organization in an email. It’s relatively simple to change the header of an email so that the From field includes anything, including the CEO’s name and title. Attackers can send an email to all employees requesting that they reply with their password. Because the email looks like it’s coming from the CEO, these types of phishing emails fool uneducated users.
upvoted 2 times
...
bugabum
4 years, 9 months ago
whaling like on kaspersky web site - In 2016, the payroll department at Snapchat received a whaling email seemingly sent from the CEO asking for employee payroll information.
upvoted 1 times
...
MagicianRecon
4 years, 10 months ago
Since the email came from CEO there would be authority and familiarity to the employee. D sounds correct. Spear fishing could be a single person or a group of ppl in a single organization
upvoted 1 times
MagicianRecon
4 years, 10 months ago
I would give this to social engineering ... hacker might be causing authority here since the email looks to be coming from CEO. This could cause the person to give out the info more quickly
upvoted 2 times
...
...
callmethefuz
4 years, 10 months ago
I said it earlier I'll say it again...comptia questions are complete garbage.
upvoted 5 times
...
SMILINJACKGS
4 years, 10 months ago
The answer is correct D - Spear Phishing. Note it was answered in question #2 Spear phishing is an e-mail spoofing fraud attempt that targets a specific organization, seeking unauthorized access to confidential data. As with the e-mail messages used in regular phishing expeditions, spear phishing messages appear to come from a trusted source. Phishing messages usually appear to come from a large and well-known company or Web site with a broad membership base, such as eBay or PayPal. In the case of spear phishing, however, the apparent source of the e-mail is likely to be an individual within the recipient's own company and generally someone in a position of authority.
upvoted 3 times
...
babaEniola
4 years, 10 months ago
Spear phishing is the fraudulent practice of sending emails ostensibly from a known or trusted sender in order to induce targeted individuals to reveal confidential information.
upvoted 1 times
...
CyberKelev
4 years, 10 months ago
Darill gibson book : Spear phishing is a targeted form of phishing. Instead of sending the email out to everyone indiscriminately, a spear phishing attack attempts to target specific groups of users, or even a single user. Spear phishing attacks may target employees within a company or customers of a company. As an example, an attacker might try to impersonate the CEO of an organization in an email
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago