What Attack Vector Is Used When Fake Onboarding Emails Contain Spoofed Links?
A new employee logs in to the email system for the first time and notices a message from human resources about onboarding. The employee hovers over a few of the links within the email and discovers that the links do not correspond to links associated with the company. Which of the following attack vectors is most likely being used?
Community Votes
55% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question distinguishes between an attack vector (social engineering/phishing) and a communication channel or compromised account scenario (business email compromise), trapping candidates who focus on the sender rather than the deceptive tactic.
This question tests the identification of phishing as a social engineering attack vector when suspicious email links are detected. While some candidates confuse the delivery medium with the attack type, the community consensus confirms that social engineering is the correct classification.
Candidates frequently select "Business email," mistaking the delivery method for the attack itself or assuming Business Email Compromise (BEC) applies simply because the message appears to come from HR, without recognizing that BEC specifically requires account takeover.
Community Discussion (17 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept Identification
This scenario describes a classic phishing attempt, which falls squarely under the social engineering attack vector. Social engineering relies on psychological manipulation to trick users into revealing sensitive information or performing actions that compromise security. In this case, the attacker impersonates Human Resources to exploit the new employee’s trust during the onboarding process.Why Option B is Correct
The question explicitly asks for the attack vector. According to CompTIA’s taxonomy, social engineering is the overarching vector that encompasses phishing, spear phishing, and pretexting. As noted by multiple community members, the mismatched URLs indicate a fraudulent attempt to deceive the recipient, which is the hallmark of social engineering. The candidate is expected to recognize that the medium (email) does not change the fundamental nature of the attack.Why Other Options Are Incorrect
- Business email: This option is a distractor. While the attack is delivered via email, "business email" refers to a communication channel, not an attack vector. Some candidates assume this points to Business Email Compromise (BEC), but BEC specifically involves the unauthorized access and use of a legitimate corporate email account. There is no indication in the scenario that HR’s account was breached; the email was likely spoofed or sent from an external domain.
- Unsecured network: An unsecured network facilitates eavesdropping or man-in-the-middle attacks, but it does not explain the presence of deliberately misleading hyperlinks designed to trick a user.
- Default credentials: This vulnerability involves using factory-set usernames and passwords. It has no relevance to deceptive email content or link manipulation.
Exam Context & Community Consensus
The split voting reflects a common point of confusion in SY0-701 questions. CompTIA prioritizes precise terminology: phishing is a technique, social engineering is the vector, and business email is merely the delivery mechanism. Recognizing this hierarchy is essential for selecting the correct answer.Official Reference
- CompTIA Security+ SY0-701 Exam Objectives: Domain 1.6 - Identify common types of vulnerabilities and threats.
- NIST Special Publication 800-50: Building an Information Technology Security Awareness and Training Program (Social Engineering Section)
- CISA Phishing and Business Email Compromise Guidelines: https://www.cisa.gov/phishing
Exam Strategy
Always distinguish between an attack vector, a technique, and a delivery medium. When CompTIA asks for the "vector," prioritize broad categories like social engineering or supply chain over specific tools or channels like email or USB drives.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →