Email Impersonation Attack Scenario: Best Classification?

Someone claiming to be from a tax agency sent an email to a team member asking for access to the project repository. Which of the following BEST describes this scenario?

  1. Social engineering
  2. Phishing Source Reference Answer
  3. Spoofing
  4. Hacking

Community Votes

B
56%
A
44%

56% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Examines the hierarchy of attack classifications where candidates must select the most specific technique over a general category when multiple options apply.

This question tests the distinction between broad social engineering tactics and specific delivery methods like phishing. The community consensus favors phishing as the best answer because it specifically targets email-based deception, whereas social engineering is too broad.

Option A is frequently chosen because attackers are manipulating people, but it fails to capture the precise digital medium that defines phishing.

Community Discussion (9 comments)

57d6284 👍 1 Selected: A
Someone reaching out to you and claiming to be someone they aren't in order to get information is, at its core, social engineering. So while it is also technically a Phishing attempt, the DNA of this attack is social engineering.
95d3b92 👍 1 Selected: B
Its an email, so therefore it’s phishing.
044f354 👍 1 Selected: B
(Best Answer) B: Phishing There is a social engineering style referred to as pretexting, where the attacker builds a believable story (pretext) to manipulate the target. The phrasing of this question COULD MISLEAD a person to think that answer A (social engineering) is correct. HOWEVER, pretexting involves direct interaction (such as phone calls or in-person deception). While the attacker here is impersonating an authority (a tax agency), the lack of direct interaction and the use of email classify it as phishing rather than pretexting. PHISHING IS AN EMAIL-BASED ATTACK, and not all phishing attempts center upon deceiving a recipient to click a malicious link. The core element of phishing is use of email as the medium, so B (phishing) is the BEST answer.
Rumchata556 👍 1 Selected: B
this is definitely phishing...
TheFai 👍 1 Selected: B
Phishing is more specific, social engineering is too broad.
TylerC 👍 1
Phishing is specifically email. It’s B.
12any 👍 1 Selected: B
Wouldn't this be B considering social engineering is a much more broad term that includes other methods . While phishing is the specific attack being used
jxh5337 👍 1 Selected: A
A social engineering
utied 👍 2 Selected: A
A. Social Engineering. Here's why: Social engineering: This involves manipulating people to gain access to sensitive information or systems. In this case, the impersonation of a tax agency official and the attempt to gain access to the project repository through a team member suggest this tactic. Phishing: While phishing often involves emails, its goal is typically to lure the recipient into clicking malicious links or attachments to steal their credentials. Here, the focus is directly on gaining access through trust and impersonation, not a malicious link. Spoofing: This involves forging data to make it appear authentic. While the email might involve spoofing the tax agency email address, it's the social engineering aspect of impersonation that's more prominent. Hacking: This involves technical methods to exploit vulnerabilities in systems. While this scenario could involve a hacker trying to exploit human behavior, the social engineering aspect takes precedence here.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Phishing is the correct choice because it specifically refers to deceptive electronic communications, typically emails, designed to trick recipients into revealing sensitive information or granting unauthorized access. While the attack employs social engineering principles, CompTIA questions consistently reward selecting the most precise technical term available. In this scenario, the use of an email to impersonate a legitimate authority aligns perfectly with standard phishing definitions.

Why the Other Options Are Wrong

Social engineering is a broad umbrella term encompassing various psychological manipulation tactics, making it less precise than phishing for an email-based attack. Spoofing refers to falsifying sender information, which may occur during phishing but does not describe the overall attack vector or intent. Hacking is a generic term for unauthorized system access and completely lacks the contextual specificity required by the scenario.

Community Comment Notes

Multiple users correctly identified that while the attack uses social engineering, phishing is the exact mechanism being deployed based on the email medium. Several comments highlight that certification exams prioritize specificity, noting that social engineering covers phone calls and physical interactions, whereas this is strictly digital. One insightful note clarifies that pretexting often implies direct interaction, further supporting email phishing as the optimal classification over broader categories.

Official Reference

Exam Strategy

Always prioritize the most specific option when both a general category and a precise technique are presented. Look for delivery mediums like email, SMS, or phone calls to quickly distinguish between phishing, smishing, vishing, and broader social engineering tactics.

Related Analysis

Practice All PK0-005 Questions

Access 102 questions with complete answers and detailed explanations.

View Full PK0-005 Practice Test →

← Back to PK0-005 Study Guide