Why Is a Duplicate Corporate Email Site Considered Impersonation?
A systems administrator is concerned users are accessing emails through a duplicate site that is not run by the company. Which of the following is used in this scenario?
Community Votes
56% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to distinguish between phishing (which requires a deceptive communication channel) and impersonation (the direct act of mimicking a legitimate web service).
This question differentiates between social engineering delivery vectors and direct service mimicry, with community consensus favoring impersonation for scenarios involving uncontrolled duplicate websites.
Candidates frequently choose Phishing because fake websites are heavily associated with phishing campaigns, overlooking that the scenario lacks any mention of a deceptive email or link used to lure users.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept Analysis
In cybersecurity, impersonation occurs when an attacker masquerades as a legitimate entity, system, or website. The scenario explicitly describes a "duplicate site that is not run by the company," which directly aligns with impersonation. The attacker has cloned or hosted a look-alike portal to deceive users into believing they are accessing the official corporate email system.Why Phishing Is Incorrect
Phishing is a strong distractor because real-world attacks often combine both tactics. However, phishing fundamentally requires a delivery mechanism—typically a fraudulent email, SMS, or voice call designed to trick a user into interacting with a malicious link. As highlighted in community discussions, the prompt provides zero details on how users were directed to the duplicate site. Without a social engineering payload or deceptive communication, Phishing is technically incomplete.Eliminating Other Options
Replication (Option B) is a standard IT operational practice used for data redundancy, load balancing, and disaster recovery; it carries no malicious intent. Smishing (Option D) is strictly SMS-based phishing, making it entirely irrelevant to web-based email access. By focusing on the exact action described—a cloned web interface—the most accurate technical term provided in the options is Impersonation.Official Reference
- CompTIA Security+ SY0-701 Exam Objectives: Social Engineering Attacks & Web Application Threats
- NIST Special Publication 800-53 Rev. 5 (SC-8, SI-10)
- OWASP Top 10: Injection & Broken Access Control (Contextual)
- CompTIA Official Study Guide: Chapter on Identity and Access Management
Exam Strategy
Always scrutinize the delivery method mentioned in the scenario. If a question describes a fake website or cloned service without mentioning a deceptive email, text, or phone call, rule out Phishing/Smishing/Vishing and look for terms like Impersonation, Spoofing, or Pharming. Focus strictly on the action described rather than broad campaign associations.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →