A systems administrator receives a text message from an unknown number claiming to be the Chief Executive Officer of the company. The message states an emergency situation requires a password reset. Which of the following threat vectors is being used?
Choose an answer
Tap an option to check your answer.
Correct answer: Smishing.
Why this is the answer
Smishing is correct because it describes a phishing attack conducted via SMS text message. The attacker is attempting to trick the recipient into revealing sensitive information (like a password) by impersonating a trusted authority (the CEO) through a text message. Typosquatting is incorrect because it involves registering domain names similar to legitimate ones to trick users who mistype URLs. Pretexting is incorrect because while it involves creating a fabricated scenario to gain information, it's a broader social engineering technique and doesn't specifically refer to the SMS delivery method. Impersonation is incorrect because it's a general social engineering tactic where an attacker pretends to be someone else, but it doesn't specify the use of text messages as the attack vector.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed