What Type of Attack Occurs When Malware Spreads via a Compromised Industry Blog?

Malware spread across a company's network after an employee visited a compromised industry blog. Which of the following best describes this type of attack?

  1. Impersonation
  2. Disinformation
  3. Watering-hole Source Reference Answer
  4. Smishing

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your ability to distinguish between targeted web-based delivery mechanisms and general social engineering techniques, with the primary trap being confusion with phishing or smishing variants.

This question examines how attackers compromise legitimate websites frequented by a specific professional group to distribute malware. The community unanimously identifies this as a watering-hole attack, emphasizing strategic targeting over broad-spectrum delivery methods.

Candidates frequently select Impersonation or Smishing due to surface-level associations with deception and digital communication. However, impersonation centers on identity spoofing rather than infrastructure compromise, while smishing exclusively utilizes SMS channels, making neither fit the described web-delivery scenario.

Community Discussion (4 comments)

chasingsummer 👍 5 Selected: C
The name is derived from predators in the natural world, who wait for an opportunity to attack their prey near watering holes.
dbrowndiver 👍 4 Selected: C
Watering-hole is the correct answer because it describes the method used by the attacker to compromise a legitimate website frequented by the target group (in this case, the industry blog) and spread malware to visitors. This strategic targeting and delivery mechanism is characteristic of a watering-hole attack.
4ddc874 👍 4 Selected: C
A watering-hole attack targets a specific group of people by compromising a website they frequently visit. In this case, the compromised industry blog acted as the "watering hole" for the employees
Shaman73 👍 4
• C. Watering-hole

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Targeted Web Compromise

A watering-hole attack occurs when threat actors identify and compromise a legitimate website that is frequently visited by a specific target audience. Much like predators in nature waiting near water sources, attackers strategically place malicious payloads on trusted sites to maximize infection rates among their intended victims. As noted by community experts, this method relies heavily on reconnaissance to understand where professionals in a given industry congregate online.

Why Option C is Correct

In this scenario, employees visiting a compromised industry blog represents a classic watering-hole setup. The attacker did not send unsolicited messages to random individuals; instead, they waited for the specific target group to voluntarily access a known resource. Once visited, the compromised site automatically delivered malware to the visitors' machines, which then spread laterally across the corporate network. This precisely matches the CompTIA Security+ definition for targeted web-based malware distribution.

Why Other Options Are Incorrect

  • Impersonation involves spoofing an identity (such as a colleague or IT administrator) to gain trust or access. While it may be used during post-exploitation, it does not describe the initial delivery mechanism via a compromised website.
  • Disinformation refers to deliberately false information spread to manipulate public perception or cause operational confusion, not technical malware deployment.
  • Smishing is a subset of phishing that specifically uses SMS or text messaging to trick users into clicking malicious links or providing credentials. It completely lacks the web-compromise and demographic targeting elements present in this scenario.

Community Consensus & Exam Focus

The unanimous 100% agreement among test-takers underscores how directly this question maps to SY0-701 objective 1.4. Memorize trigger phrases like "compromised website," "frequently visited by targets," and "industry-specific portal" as immediate indicators for watering-hole. Always evaluate the delivery channel and target specificity before defaulting to broader social engineering categories.

Official Reference

  • CompTIA Security+ SY0-701 Objective 1.4: Threat Actors, Tactics, and Techniques
  • NIST SP 800-61 Rev. 2: Computer Security Incident Handling Guide (Watering Hole Attack Section)
  • CISA Cybersecurity Information Sharing Act (CISA) Guidelines on Targeted Web Compromise

Exam Strategy

When analyzing attack vector questions, always map the delivery method to the target audience first. If a threat leverages a trusted site commonly visited by a specific demographic, immediately rule out broad-spectrum methods like spam or generic phishing and prioritize targeted environmental attacks.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide