Email Impersonation Attack Scenario: Best Classification?
Someone claiming to be from a tax agency sent an email to a team member asking for access to the project repository. Which of the following BEST describes this scenario?
Community Votes
56% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Examines the hierarchy of attack classifications where candidates must select the most specific technique over a general category when multiple options apply.
This question tests the distinction between broad social engineering tactics and specific delivery methods like phishing. The community consensus favors phishing as the best answer because it specifically targets email-based deception, whereas social engineering is too broad.
Option A is frequently chosen because attackers are manipulating people, but it fails to capture the precise digital medium that defines phishing.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Phishing is the correct choice because it specifically refers to deceptive electronic communications, typically emails, designed to trick recipients into revealing sensitive information or granting unauthorized access. While the attack employs social engineering principles, CompTIA questions consistently reward selecting the most precise technical term available. In this scenario, the use of an email to impersonate a legitimate authority aligns perfectly with standard phishing definitions.Why the Other Options Are Wrong
Social engineering is a broad umbrella term encompassing various psychological manipulation tactics, making it less precise than phishing for an email-based attack. Spoofing refers to falsifying sender information, which may occur during phishing but does not describe the overall attack vector or intent. Hacking is a generic term for unauthorized system access and completely lacks the contextual specificity required by the scenario.Community Comment Notes
Multiple users correctly identified that while the attack uses social engineering, phishing is the exact mechanism being deployed based on the email medium. Several comments highlight that certification exams prioritize specificity, noting that social engineering covers phone calls and physical interactions, whereas this is strictly digital. One insightful note clarifies that pretexting often implies direct interaction, further supporting email phishing as the optimal classification over broader categories.Official Reference
Exam Strategy
Always prioritize the most specific option when both a general category and a precise technique are presented. Look for delivery mediums like email, SMS, or phone calls to quickly distinguish between phishing, smishing, vishing, and broader social engineering tactics.
Related Analysis
Practice All PK0-005 Questions
Access 102 questions with complete answers and detailed explanations.
View Full PK0-005 Practice Test →