Which Social Engineering Attack Occurred After an Employee Submitted Credentials via a Fake Payment Email?
An employee clicked a link in an email from a payment website that asked the employee to update contact information. The employee entered the log-in information but received a “page not found” error message. Which of the following types of social engineering attacks occurred?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to classify the overarching attack vector versus its underlying tactics, with the common trap being confusion between the delivery method (Phishing) and the disguise technique (Brand Impersonation).
This question tests the identification of phishing attacks where users are tricked into submitting credentials through fraudulent emails. The community overwhelmingly agrees on Phishing as the correct answer, emphasizing that broad attack categories take precedence over specific techniques in SY0-701.
Candidates frequently select Brand Impersonation because the scenario highlights a fake payment website, causing them to focus on the deception rather than the delivery channel. However, since the attack was executed via a deceptive email designed to harvest credentials, Phishing remains the correct and officially accepted classification.
Community Discussion (17 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Correct Answer: Phishing
The scenario describes a classic phishing attack, which CompTIA defines as a social engineering technique where attackers send fraudulent communications—typically emails—that appear to originate from reputable entities to induce individuals to reveal sensitive information. In this case, the employee received an email claiming to be from a payment processor, clicked a malicious link, and submitted login credentials. Even though the destination returned a “page not found” error, the attacker successfully intercepted the data during the submission process. As highlighted by multiple community contributors, this aligns perfectly with the foundational SY0-701 definition of phishing.
Why the Other Options Are Incorrect
- Brand Impersonation: While the attacker did mimic a legitimate brand, brand impersonation is technically a tactic or technique nested within a phishing campaign. CompTIA exams expect candidates to identify the primary attack type first. Only if the question specifically asked for the "technique" rather than the "attack type" would this be the optimal choice.
- Pretexting: This involves fabricating an elaborate scenario to build rapport and trust before extracting information. Unlike the single-email credential harvest described here, pretexting relies on sustained interpersonal manipulation rather than automated or semi-automated deceptive links.
- Typosquatting: This occurs when attackers register domain names that visually resemble legitimate ones (e.g., paying-site.com vs. paymentsite.com) to trick users. The scenario makes no mention of misspelled URLs or domain registration tricks, focusing solely on the email delivery and credential submission.
Community Insights & Exam Context
The SY0-701 exam consistently tests the hierarchy of security terminology, prioritizing broad categories unless explicit wording directs otherwise. Community feedback reinforces that while brand impersonation accurately describes the visual disguise, phishing correctly identifies the delivery mechanism and overall attack classification. As one candidate noted, focusing on the email-based credential harvesting aligns directly with CompTIA’s standardized taxonomy. Always map the communication channel to the attack family first, then refine based on specific question phrasing.
Official Reference
Exam Strategy
When answering social engineering questions, always match the delivery method to the attack category first; email-based credential harvesting is almost universally classified as phishing unless the question explicitly isolates a sub-tactic. Additionally, scan for trigger words like "technique," "tactic," or "method" to determine whether a narrower answer is required over the broader attack type.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →