What Attack Vector Is Used When Fake Onboarding Emails Contain Spoofed Links?

A new employee logs in to the email system for the first time and notices a message from human resources about onboarding. The employee hovers over a few of the links within the email and discovers that the links do not correspond to links associated with the company. Which of the following attack vectors is most likely being used?

  1. Business email
  2. Social engineering Source Reference Answer
  3. Unsecured network
  4. Default credentials

Community Votes

B
55%
A
45%

55% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question distinguishes between an attack vector (social engineering/phishing) and a communication channel or compromised account scenario (business email compromise), trapping candidates who focus on the sender rather than the deceptive tactic.

This question tests the identification of phishing as a social engineering attack vector when suspicious email links are detected. While some candidates confuse the delivery medium with the attack type, the community consensus confirms that social engineering is the correct classification.

Candidates frequently select "Business email," mistaking the delivery method for the attack itself or assuming Business Email Compromise (BEC) applies simply because the message appears to come from HR, without recognizing that BEC specifically requires account takeover.

Community Discussion (17 comments)

c80f5c5 👍 17 Selected: A
Business email compromise (BEC) is an email-based social engineering attack Social engineering refers to all the techniques used to coerce or talk a victim into revealing information that someone can use to perform malicious activities and render an organization or individual vulnerable to further attacks Answer: A- Business email
Twphill 👍 10 Selected: B
Social engineering is an attack vector, while Business email is an attack surface. If it said Business Email Compromise, that would be an attack vector.
Linas312 👍 2 Selected: B
Typical bad wording.. IF its a hr compromised account then could be A? but even a is it BEC they are referring to? vague for no reason, they can really blindly pick either A or B and decide which they will accept..
WifiWan 👍 1 Selected: A
biz email
mejestique 👍 1 Selected: B
The correct answer is: B. Social engineering Explanation: This scenario describes a phishing attack, a type of social engineering where an attacker sends fraudulent emails pretending to be from a trusted source (in this case, human resources). The mismatched links suggest an attempt to deceive the employee into clicking a malicious link, possibly leading to credential theft or malware installation. Other options explained: A. Business email – Likely refers to Business Email Compromise (BEC), which involves targeted attacks on executives or finance personnel rather than generic phishing. C. Unsecured network – There is no indication that the employee is on an insecure network; the issue is the deceptive email content. D. Default credentials – This applies to systems left with manufacturer-set passwords, which is unrelated to phishing emails. Since the attacker is attempting to manipulate human behavior to gain access, this is a social engineering attack.
TmNvrWts 👍 1 Selected: B
Why not the others? A. Business email (compromise) – This involves an attacker gaining control of a legitimate business email account, but in this case, the email appears to be a fake rather than a compromised real account. C. Unsecured network – An unsecured network could allow data interception, but it wouldn’t cause misleading links in an email. D. Default credentials – This refers to using factory-set usernames and passwords, which is unrelated to this phishing attempt.
pindinga1 👍 2 Selected: A
Business email compromise (BEC) is an email-based social engineering attack
esko636 👍 1 Selected: B
This is a social engineering attack done through phishing. Phishing typically involves sending mass emails to a large number of recipients, aiming to trick them into clicking on malicious links or providing sensitive information. The email in this scenario seems to fit this pattern, as it contains suspicious links that do not correspond to the company's legitimate links. Business Email Compromise (BEC), on the other hand, is more targeted. It often involves attackers gaining access to a legitimate business email account and using it to send fraudulent emails to specific individuals within the organization. These emails usually request actions like transferring funds or sharing confidential information. BEC attacks are generally more sophisticated and personalized compared to phishing.
Damique 👍 1 Selected: B
It is not business email because this term refers to emails sent using an organization's domain and infrastructure, not necessarily indicative of an attack.
BevMe 👍 1 Selected: B
Social Engineering is right.
3dk1 👍 1 Selected: A
This lines up with A
PAWarriors 👍 4 Selected: A
The correct answer is A. > This is an example of Business Email Compromise (BEC). BEC is a type of phishing attack that usually targets businesses by using one of their internal email accounts to get other employees to perform some kind of malicious actions on behalf of the attacker. In this scenario the email came from human resources, indicating that this is a BEC.
Ambaj 👍 3 Selected: B
B. Social engineering
ofolan 👍 5 Selected: B
B. Social engineering Social engineering involves manipulating individuals into divulging confidential information or performing actions that compromise security. In this case, the email containing suspicious links is an example of a phishing attempt, where attackers try to deceive the employee into clicking on malicious links that may lead to fraudulent sites or compromise their credentials.
17f9ef0 👍 2 Selected: B
Answer is B
a73231e 👍 6
I think that this question is a bit tricky in its language and its options of available answers. I would agree with A if it actually said " Business Email Compromise" but it simply says business email. B would be the correct answer because its actually mentioning a form of attack. Attack vector is literally referring to what kind of attack is being shown.
Glacier88 👍 4 Selected: B
Social engineering: This refers to techniques used to manipulate people into performing actions or divulging confidential information. In this case, the attacker is using a legitimate-looking email from human resources to trick the new employee into clicking on malicious links. Business email compromise (BEC): While BEC can involve emails from legitimate-looking senders, it typically targets high-profile individuals or organizations for financial gain. In this case, the target is a new employee, and the goal seems to be to compromise their system.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept Identification

This scenario describes a classic phishing attempt, which falls squarely under the social engineering attack vector. Social engineering relies on psychological manipulation to trick users into revealing sensitive information or performing actions that compromise security. In this case, the attacker impersonates Human Resources to exploit the new employee’s trust during the onboarding process.

Why Option B is Correct

The question explicitly asks for the attack vector. According to CompTIA’s taxonomy, social engineering is the overarching vector that encompasses phishing, spear phishing, and pretexting. As noted by multiple community members, the mismatched URLs indicate a fraudulent attempt to deceive the recipient, which is the hallmark of social engineering. The candidate is expected to recognize that the medium (email) does not change the fundamental nature of the attack.

Why Other Options Are Incorrect

  • Business email: This option is a distractor. While the attack is delivered via email, "business email" refers to a communication channel, not an attack vector. Some candidates assume this points to Business Email Compromise (BEC), but BEC specifically involves the unauthorized access and use of a legitimate corporate email account. There is no indication in the scenario that HR’s account was breached; the email was likely spoofed or sent from an external domain.
  • Unsecured network: An unsecured network facilitates eavesdropping or man-in-the-middle attacks, but it does not explain the presence of deliberately misleading hyperlinks designed to trick a user.
  • Default credentials: This vulnerability involves using factory-set usernames and passwords. It has no relevance to deceptive email content or link manipulation.

Exam Context & Community Consensus

The split voting reflects a common point of confusion in SY0-701 questions. CompTIA prioritizes precise terminology: phishing is a technique, social engineering is the vector, and business email is merely the delivery mechanism. Recognizing this hierarchy is essential for selecting the correct answer.

Official Reference

  • CompTIA Security+ SY0-701 Exam Objectives: Domain 1.6 - Identify common types of vulnerabilities and threats.
  • NIST Special Publication 800-50: Building an Information Technology Security Awareness and Training Program (Social Engineering Section)
  • CISA Phishing and Business Email Compromise Guidelines: https://www.cisa.gov/phishing

Exam Strategy

Always distinguish between an attack vector, a technique, and a delivery medium. When CompTIA asks for the "vector," prioritize broad categories like social engineering or supply chain over specific tools or channels like email or USB drives.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide