A new employee logs in to the email system for the first time and notices a message from human resources about onboarding. The employee hovers over a few of the links within the email and discovers that the links do not correspond to links associated with the company. Which of the following attack vectors is most likely being used?
Choose an answer
Tap an option to check your answer.
Correct answer: Social engineering.
Why this is the answer
Social engineering is the most likely attack vector. The attacker is manipulating the new employee into clicking malicious links by impersonating a trusted source (Human Resources) and leveraging the employee's expectation of onboarding information. This type of attack preys on human psychology rather than technical vulnerabilities. Business email is too broad; while the attack uses email, "social engineering" describes the method of deception. An unsecured network might facilitate the attack but isn't the attack vector itself. Default credentials relate to authentication weaknesses, not the deceptive content of an email.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed