Courseiva
Security Concepts →hardMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is investigating an incident where an employee received an email that appeared to be from the company's IT department, requesting the employee to verify their account by clicking a link and entering their credentials. The employee complied, and later the attacker used those credentials to access the corporate VPN. Which combination of attack types best describes this incident?

⚠ Common exam trap

The trap is misclassifying the attack as pretexting or man-in-the-middle. Pretexting is a component of spear phishing but not the primary label; man-in-the-middle requires interception. Candidates might also think privilege escalation occurred because the attacker accessed the VPN, but that's unauthorized access, not escalation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spear phishing and credential theft

The incident involves a targeted email that appears to be from the IT department, requesting credential verification—this is spear phishing because it's tailored to the organization. The employee providing credentials leads to credential theft, which the attacker then uses to access the VPN. Thus, spear phishing and credential theft best describe the attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pretexting and privilege escalation

    Why it's wrong here

    Pretexting is a fabricated narrative, which loosely fits the fake IT email, but privilege escalation means gaining higher permissions than granted; the attacker reused the employee's existing VPN access without elevating rights. Pretexting tempts because a story was told, yet the credential theft via link is phishing.

  • ✗

    Phishing and man-in-the-middle

    Why it's wrong here

    Phishing correctly describes the deceptive email, but man-in-the-middle requires intercepting and relaying an existing session between two parties. No interception occurred; the attacker harvested credentials and authenticated separately. MITM tempts whenever credentials are stolen, yet the second attack here is credential reuse, not session interception.

  • ✓

    Spear phishing and credential theft

    Why this is correct

    The email targeted a specific employee while impersonating internal IT, which is spear phishing rather than generic phishing. The captured credentials were then reused to access the corporate VPN, directly constituting credential theft, matching both elements the scenario describes.

  • ✗

    Vishing and brute force

    Why it's wrong here

    Vishing is voice-based social engineering, and brute force means guessing credentials repeatedly; neither occurred, since the email link harvested credentials directly and the attacker simply logged in. These are tempting when phone calls or password guessing appear, but the stem describes email deception and credential reuse.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.