Which Attack Vector Caused the Resume-Based Ransomware Infection?

Answer Correct answer: A — The resume attachment opened from a message is the spear-phishing vector that delivered the ransomware.

A user's workstation becomes unresponsive and displays a ransom note demanding payment to decrypt files. Before the attack, the user opened a resume they received in a message, browsed the company's website, and installed OS updates. Which of the following is the most likely vector of this attack?

  1. Spear-phishing attachment Correct Answer
  2. Watering hole
  3. Infected website
  4. Typosquatting

Community Votes

A
83%
B
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

You must separate the single unsolicited, attacker-controlled artifact (the resume attachment) from routine benign activity (corporate website browsing, OS updates); the trap is treating any website visit as a watering hole.

A workstation encrypted by ransomware right after a user opened a resume received in a message points to a spear-phishing attachment as the initial vector. This page confirms why the resume — not the company website visit or the OS update — is the most likely vector on the SY0-701 exam.

The most common wrong pick is B, watering hole, because test-takers see 'browsed the company's website' and assume it was compromised; a watering hole requires evidence that attackers pre-infected a trusted site, which the stem never provides.

Community Discussion (4 comments)

Fourgehan 👍 1 Selected: A
The most likely vector in this scenario is the resume the user opened from a message. This strongly suggests a spear-phishing attack, where attackers send a targeted email with a malicious attachment (in this case, the resume). Once opened, the attachment likely executed malware that encrypted the user's files and displayed the ransom note
saba263 👍 4 Selected: A
The most likely vector of the ransomware attack is the spear-phishing attachment from the resume the user opened in a message. Spear-phishing is a targeted attack where attackers send malicious attachments or links that appear legitimate. In this case, the resume attachment likely contained malicious code that executed the ransomware when opened. Why Not the Other Options? B. Watering hole: A watering hole attack compromises a trusted website that the target frequently visits. While the user browsed the company's website, there’s no evidence that the website itself was infected or used as the attack vector.
fd4ea1a 👍 1 Selected: B
Watering holes are usually set up somewhere that you know people will go and set a trap there. he went to the companys website, and installed the OS update. It would be a sprear phissing incident if the email he recieved had the attachment, but instead he went to the watering hole. there is a case for both.
s_plus 👍 1
What is it: A type of social engineering attack, Spear Phishing is a more targeted version of phishing, where the attacker researches their target and makes the scam appear more legitimate. How it works: It usually starts with the attacker researching the target(s), then crafting an email (disguised as a trustworthy entity) tailored to the target's interests or habits, leading them to click on malicious links or attachments.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The ransom note follows exactly one user action that introduced untrusted outside content: opening a resume received in a message. Spear-phishing is a targeted social-engineering attack in which the attacker crafts a plausible lure — here a job applicant's resume — and delivers malware as an attachment or link; execution of that attachment is the textbook ransomware initial-access path (MITRE ATT&CK T1566.001). The other two actions in the stem, browsing the company's own website and installing OS updates, are routine trusted operations that do not normally deliver an attacker payload. Because the question asks for the most likely vector, the unsolicited-but-opened resume outweighs any speculative compromise of the corporate site. Answer A therefore matches both vendor threat-vector doctrine and the exam's intent.

Why the Other Options Are Wrong

B (watering hole) requires the attacker to first compromise a site the target is known to frequent and plant an exploit there; nothing in the stem says the company website was compromised or served a drive-by payload, and the user only browsed it as a normal employee would. C (infected website) is a vaguer restatement of the same idea and is even weaker, because merely visiting a legitimate corporate site is not evidence of infection — the stem deliberately separates that benign action from the attack to test the distinction. D (typosquatting) depends on the user mistyping a domain and landing on a look-alike site, which is never described. Only option A accounts for a malicious payload arriving through a channel the user actually opened.

Community Comment Notes

saba263 and Fourgehan both selected A, reasoning that the resume opened "from a message" is the targeted lure and that the attachment likely executed the ransomware on open. fd4ea1a chose B but conceded "there is a case for both," arguing the victim visited the company website — a useful reminder that exam stems deliberately include benign look-alike distractors that must be discounted. s_plus's definition of spear-phishing as a targeted, researched social-engineering attack reinforces why the personalized resume is the discriminator rather than a randomly malicious site.

Official Reference

Exam Strategy

When a stem lists several user actions, find the one that delivers unsolicited external content — that is the vector — and treat updates and intranet browsing as noise. Ranking likelihood, not just possibility, is what separates A from B and C here.

Frequently Asked Questions

Why is a watering hole (B) less likely than a spear-phishing attachment here?

The only attacker-influenced content the user touched was the resume received in a message; the company website visit and OS update were routine actions with no sign the site was compromised.

How does typosquatting (D) differ from this scenario?

Typosquatting requires the user to mistype a URL and land on a look-alike domain, but no browsing mistake is described — the malicious content arrived unsolicited in a message.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide