Which Attack Vector Caused the Resume-Based Ransomware Infection?
A user's workstation becomes unresponsive and displays a ransom note demanding payment to decrypt files. Before the attack, the user opened a resume they received in a message, browsed the company's website, and installed OS updates. Which of the following is the most likely vector of this attack?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
You must separate the single unsolicited, attacker-controlled artifact (the resume attachment) from routine benign activity (corporate website browsing, OS updates); the trap is treating any website visit as a watering hole.
A workstation encrypted by ransomware right after a user opened a resume received in a message points to a spear-phishing attachment as the initial vector. This page confirms why the resume — not the company website visit or the OS update — is the most likely vector on the SY0-701 exam.
The most common wrong pick is B, watering hole, because test-takers see 'browsed the company's website' and assume it was compromised; a watering hole requires evidence that attackers pre-infected a trusted site, which the stem never provides.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The ransom note follows exactly one user action that introduced untrusted outside content: opening a resume received in a message. Spear-phishing is a targeted social-engineering attack in which the attacker crafts a plausible lure — here a job applicant's resume — and delivers malware as an attachment or link; execution of that attachment is the textbook ransomware initial-access path (MITRE ATT&CK T1566.001). The other two actions in the stem, browsing the company's own website and installing OS updates, are routine trusted operations that do not normally deliver an attacker payload. Because the question asks for the most likely vector, the unsolicited-but-opened resume outweighs any speculative compromise of the corporate site. Answer A therefore matches both vendor threat-vector doctrine and the exam's intent.Why the Other Options Are Wrong
B (watering hole) requires the attacker to first compromise a site the target is known to frequent and plant an exploit there; nothing in the stem says the company website was compromised or served a drive-by payload, and the user only browsed it as a normal employee would. C (infected website) is a vaguer restatement of the same idea and is even weaker, because merely visiting a legitimate corporate site is not evidence of infection — the stem deliberately separates that benign action from the attack to test the distinction. D (typosquatting) depends on the user mistyping a domain and landing on a look-alike site, which is never described. Only option A accounts for a malicious payload arriving through a channel the user actually opened.Community Comment Notes
saba263 and Fourgehan both selected A, reasoning that the resume opened "from a message" is the targeted lure and that the attachment likely executed the ransomware on open. fd4ea1a chose B but conceded "there is a case for both," arguing the victim visited the company website — a useful reminder that exam stems deliberately include benign look-alike distractors that must be discounted. s_plus's definition of spear-phishing as a targeted, researched social-engineering attack reinforces why the personalized resume is the discriminator rather than a randomly malicious site.Official Reference
Exam Strategy
When a stem lists several user actions, find the one that delivers unsolicited external content — that is the vector — and treat updates and intranet browsing as noise. Ranking likelihood, not just possibility, is what separates A from B and C here.
Frequently Asked Questions
Why is a watering hole (B) less likely than a spear-phishing attachment here?
The only attacker-influenced content the user touched was the resume received in a message; the company website visit and OS update were routine actions with no sign the site was compromised.
How does typosquatting (D) differ from this scenario?
Typosquatting requires the user to mistype a URL and land on a look-alike domain, but no browsing mistake is described — the malicious content arrived unsolicited in a message.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →