Why Is a Duplicate Corporate Email Site Considered Impersonation?

A systems administrator is concerned users are accessing emails through a duplicate site that is not run by the company. Which of the following is used in this scenario?

  1. Impersonation Source Reference Answer
  2. Replication
  3. Phishing
  4. Smishing

Community Votes

A
56%
C
44%

56% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to distinguish between phishing (which requires a deceptive communication channel) and impersonation (the direct act of mimicking a legitimate web service).

This question differentiates between social engineering delivery vectors and direct service mimicry, with community consensus favoring impersonation for scenarios involving uncontrolled duplicate websites.

Candidates frequently choose Phishing because fake websites are heavily associated with phishing campaigns, overlooking that the scenario lacks any mention of a deceptive email or link used to lure users.

Community Discussion (8 comments)

jbmac 👍 5 Selected: A
The correct answer is: A. Impersonation Explanation: Impersonation refers to an attack where a malicious actor pretends to be someone else, typically by mimicking a legitimate website, email address, or service. In this scenario, the users are accessing emails through a duplicate site that is not controlled by the company, which indicates that the attacker is impersonating the company’s legitimate email platform to deceive users.
timotei 👍 1 Selected: A
A, They are accessing the email through duplicate site not access the site through email.
Konversation 👍 1 Selected: A
Bad question by CompTIA. A & B are correct, theoretically. Impersonation (as part of pharming) "is an attack in which a request for a website, typically an e-commerce site, is redirected to a similar-looking, but fake, website." (Sec+ Student Guide). Depending from the source is pharming a sub category of phishing. Even the Sec+ Student Guide states: "Phishing and pharming both depend on impersonation to succeed. ..." I guess, what CompTIA wanted to test, is if we understand the difference between phishing, smishing, vishing, and pharming. That's why Igo with A.
9149f41 👍 4 Selected: C
The answer is not impersonation, because impersonation refers to: More about pretending to be someone Usually person-to-person deception Doesn't typically involve duplicate sites
Eracle 👍 3 Selected: C
Why not C: impersonation refers to pretending to be someone else, but does not necessarily imply a fake site. So, i think the correct answer is phishing
9149f41 👍 4 Selected: C
The correct answer is C. Phishing. Phishing involves creating a fake website or email that mimics a legitimate one to trick users into providing sensitive information, such as login credentials. In this scenario, users are accessing emails through a duplicate site that is not run by the company, which is a classic example of phishing.
admcdaniel 👍 4 Selected: A
Impersonation, no reference to social engineering email, text, or call. Simply a website that is impersonating another.
Fhaddad81 👍 3 Selected: A
this is the explanation of Impersonation

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept Analysis

In cybersecurity, impersonation occurs when an attacker masquerades as a legitimate entity, system, or website. The scenario explicitly describes a "duplicate site that is not run by the company," which directly aligns with impersonation. The attacker has cloned or hosted a look-alike portal to deceive users into believing they are accessing the official corporate email system.

Why Phishing Is Incorrect

Phishing is a strong distractor because real-world attacks often combine both tactics. However, phishing fundamentally requires a delivery mechanism—typically a fraudulent email, SMS, or voice call designed to trick a user into interacting with a malicious link. As highlighted in community discussions, the prompt provides zero details on how users were directed to the duplicate site. Without a social engineering payload or deceptive communication, Phishing is technically incomplete.

Eliminating Other Options

Replication (Option B) is a standard IT operational practice used for data redundancy, load balancing, and disaster recovery; it carries no malicious intent. Smishing (Option D) is strictly SMS-based phishing, making it entirely irrelevant to web-based email access. By focusing on the exact action described—a cloned web interface—the most accurate technical term provided in the options is Impersonation.

Official Reference

  • CompTIA Security+ SY0-701 Exam Objectives: Social Engineering Attacks & Web Application Threats
  • NIST Special Publication 800-53 Rev. 5 (SC-8, SI-10)
  • OWASP Top 10: Injection & Broken Access Control (Contextual)
  • CompTIA Official Study Guide: Chapter on Identity and Access Management

Exam Strategy

Always scrutinize the delivery method mentioned in the scenario. If a question describes a fake website or cloned service without mentioning a deceptive email, text, or phone call, rule out Phishing/Smishing/Vishing and look for terms like Impersonation, Spoofing, or Pharming. Focus strictly on the action described rather than broad campaign associations.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide