Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The email contains a sense of urgency. Which type of attack is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

Phishing is a social engineering attack that uses deceptive emails to trick recipients into revealing sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is a social-engineering technique using a fabricated scenario, typically by phone or in person, to extract information through a false identity. It is tempting because the email does invent a bank scenario, but pretexting lacks the mass email lure and malicious link that define phishing.

  • ✗

    Vishing

    Why it's wrong here

    Vishing is voice phishing conducted over telephone calls, using spoken conversation to manipulate the victim. It is tempting because it also impersonates a trusted organisation, but this attack arrives by email with a clickable link, so no voice channel is involved.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing targets specific, previously researched individuals or small groups with tailored messages, whereas this email is an untargeted bulk lure impersonating a bank. It is tempting because the message is crafted to look legitimate, but the absence of individual reconnaissance makes it generic phishing.

  • ✓

    Phishing

    Why this is correct

    The email spoofs a trusted bank, demands urgent verification and harvests credentials via a link, matching phishing's social-engineering mechanism. It satisfies the stem's constraints: forged sender identity, urgency pressure and a credential-capture link, distinguishing it from technical exploits that need no user interaction.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.