Definition of Phishing in Cybersecurity
What is the definition of phishing?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between general bulk spam and targeted fraudulent impersonation; the trap is confusing phishing with spoofing or spear phishing.
This question tests the precise definition of phishing versus related social engineering attacks. The correct answer identifies phishing as sending fraudulent communications appearing to come from a reputable source.
Option A is incorrect because it describes spear phishing (targeted) or email spoofing specifically, whereas phishing is broader. Option B describes credential harvesting via fake sites (a technique often used in phishing but not the definition itself). Option C defines spam.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Phishing is broadly defined as the practice of sending fraudulent communications that appear to come from a legitimate and reputable source. The primary goal is to steal sensitive data, gain access to accounts, or install malware by tricking the recipient. Option D captures this essence perfectly by focusing on the appearance of legitimacy from a reputable source.Why the Other Options Are Wrong
Option A describes spear phishing, which targets specific individuals or organizations, or simply email spoofing. Option B describes a specific tactic (credential theft via fake websites) often associated with phishing but is too narrow to be the general definition. Option C defines spam (unsolicited bulk communication), which lacks the element of deception/impersonation central to phishing.Community Comment Notes
Community consensus strongly supports option D. Users frequently cite Cisco's documentation, noting that phishing involves fraudulent communications appearing from a legitimate source. One user clarified that option A is incorrect because phishing is not limited to email spoofing attacks against specific targets, reinforcing that D is the broader, correct definition.Official Reference
Exam Strategy
When defining security terms, look for the most comprehensive description that covers the core mechanism (deception/impersonation) rather than specific examples or narrower variants like spear phishing or spam.
Frequently Asked Questions
Is phishing the same as spam?
No. Spam is unsolicited bulk communication (Option C). Phishing involves fraud and impersonation to deceive users (Option D).
How does phishing differ from spear phishing?
Phishing is broad and targets anyone (Option D). Spear phishing targets specific individuals or organizations (Option A).