Which Social Engineering Attack Occurred After an Employee Submitted Credentials via a Fake Payment Email?

An employee clicked a link in an email from a payment website that asked the employee to update contact information. The employee entered the log-in information but received a “page not found” error message. Which of the following types of social engineering attacks occurred?

  1. Brand impersonation
  2. Pretexting
  3. Typosquatting
  4. Phishing Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to classify the overarching attack vector versus its underlying tactics, with the common trap being confusion between the delivery method (Phishing) and the disguise technique (Brand Impersonation).

This question tests the identification of phishing attacks where users are tricked into submitting credentials through fraudulent emails. The community overwhelmingly agrees on Phishing as the correct answer, emphasizing that broad attack categories take precedence over specific techniques in SY0-701.

Candidates frequently select Brand Impersonation because the scenario highlights a fake payment website, causing them to focus on the deception rather than the delivery channel. However, since the attack was executed via a deceptive email designed to harvest credentials, Phishing remains the correct and officially accepted classification.

Community Discussion (17 comments)

Mehsotopes 👍 13 Selected: D
Phishing is the fraudulent practice of sending emails, or other messages to cause an individual to reveal personal information. This question does not specify if this email was pretexting to butter up the employee, or make email more convincing (pretexting), nor does it specify this email being a trusted brand, or waiting on employee to type incorrectly to steal information.
JackExam2025 👍 2 Selected: D
Phishing is a type of social engineering attack where attackers trick individuals into revealing sensitive information (such as login credentials) by pretending to be a legitimate entity.
examtaker01 👍 3 Selected: D
The correct answer is: ✅ D. Phishing Breakdown; The scenario describes a classic phishing attack, where: The employee receives an email claiming to be from a payment website. The email contains a malicious link that leads to a fake login page. The employee enters their credentials, but instead of proceeding, they get a "page not found" error (likely because the attacker has already captured the credentials). Why A is not the answer; A. Brand impersonation Brand impersonation happens when an attacker pretends to be a legitimate company (e.g., fake social media pages or fake customer service numbers). While phishing often involves brand impersonation, the key element here is credential theft, making phishing the better answer.
Cyberfox9001 👍 1 Selected: D
Phishing consists of sending emails that contain fake information or to acquire information from the user who opens an email.
Hasss 👍 1 Selected: D
They are basically fishing for information that they arent allowed to be privy to.
AryzBeats 👍 1 Selected: D
Phishing is a practice used for sending fraudulent emails in hopes of retrieving sensitive data
deedee2025 👍 1 Selected: D
if a Technique was asked then Brand impersonation would have been the best answer....the best answer is phishing because phishing is a type of attack that involves fraudulent practice of sending email
HungryRightNow 👍 1 Selected: A
This isn't what most people said, so tell me why this wrong: Phishing isn't a wrong answer, but Brand Impersonation -- which can be a type of phishing -- is a the BEST answer.
way12 👍 1 Selected: D
phishing takes place when you receive email asking for personnel information.
JRCHENRY 👍 1 Selected: D
Phishing is a social engineering attack to trick people into releasing their personal information
88d4601 👍 1 Selected: C
Phishing
Juls74 👍 1 Selected: D
Phishing is a social engineering attack where attackers send fraudulent emails or messages that appear to come from reputable sources. These emails often contain links to fake websites that steal personal information, such as login credentials. In this case, the employee was tricked into entering their login information on a phony payment website, resulting in a “page not found” error message.
Gominolo 👍 1 Selected: A
A. Brand impersonation. "In the context of email security, brand impersonation is a form of phishing cyber-attack that aims to solicit sensitive information from victims by posing as a legitimate brand." That reply is more accurate than just Phishing.
[Removed] 👍 1 Selected: D
D. Phishing Phishing involves tricking individuals into providing sensitive information, such as login credentials, by pretending to be a legitimate entity. In this case, the employee was deceived into entering their login information on a fake website that impersonated a payment website.
Luchis_69 👍 2 Selected: D
This ACL configuration first permits outbound DNS traffic originating from the device with the IP address 10.50.10.25 and then denies all other outbound DNS traffic.
shady23 👍 1 Selected: D
D. Phishing
Jonserver 👍 2
Phishing

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Correct Answer: Phishing

The scenario describes a classic phishing attack, which CompTIA defines as a social engineering technique where attackers send fraudulent communications—typically emails—that appear to originate from reputable entities to induce individuals to reveal sensitive information. In this case, the employee received an email claiming to be from a payment processor, clicked a malicious link, and submitted login credentials. Even though the destination returned a “page not found” error, the attacker successfully intercepted the data during the submission process. As highlighted by multiple community contributors, this aligns perfectly with the foundational SY0-701 definition of phishing.

Why the Other Options Are Incorrect

  • Brand Impersonation: While the attacker did mimic a legitimate brand, brand impersonation is technically a tactic or technique nested within a phishing campaign. CompTIA exams expect candidates to identify the primary attack type first. Only if the question specifically asked for the "technique" rather than the "attack type" would this be the optimal choice.
  • Pretexting: This involves fabricating an elaborate scenario to build rapport and trust before extracting information. Unlike the single-email credential harvest described here, pretexting relies on sustained interpersonal manipulation rather than automated or semi-automated deceptive links.
  • Typosquatting: This occurs when attackers register domain names that visually resemble legitimate ones (e.g., paying-site.com vs. paymentsite.com) to trick users. The scenario makes no mention of misspelled URLs or domain registration tricks, focusing solely on the email delivery and credential submission.

Community Insights & Exam Context

The SY0-701 exam consistently tests the hierarchy of security terminology, prioritizing broad categories unless explicit wording directs otherwise. Community feedback reinforces that while brand impersonation accurately describes the visual disguise, phishing correctly identifies the delivery mechanism and overall attack classification. As one candidate noted, focusing on the email-based credential harvesting aligns directly with CompTIA’s standardized taxonomy. Always map the communication channel to the attack family first, then refine based on specific question phrasing.

Official Reference

Exam Strategy

When answering social engineering questions, always match the delivery method to the attack category first; email-based credential harvesting is almost universally classified as phishing unless the question explicitly isolates a sub-tactic. Additionally, scan for trigger words like "technique," "tactic," or "method" to determine whether a narrower answer is required over the broader attack type.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide