A user's workstation becomes unresponsive and displays a ransom note demanding payment to decrypt files. Before the attack, the user opened a resume they received in a message, browsed the company's website, and installed OS updates. Which of the following is the most likely vector of this attack?
Choose an answer
Tap an option to check your answer.
Correct answer: Spear-phishing attachment.
Why this is the answer
The most likely vector is a spear-phishing attachment. The user opened a resume received in a message, which is a classic delivery method for malware via a malicious attachment. Spear phishing targets specific individuals with personalized lures, like a resume for someone involved in hiring, making it highly effective. Watering hole attacks involve compromising a website frequently visited by a target group, which doesn't fit the scenario of opening an attachment. An infected website could be a vector, but the direct action of opening a resume attachment points more strongly to spear phishing. Typosquatting involves registering domain names similar to legitimate ones to trick users, which is not indicated here. Installing OS updates is a security best practice and unlikely to be the cause of the infection.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed