200-201 Security Concepts Practice Question
An attacker sends an email posing as the company's IT department, asking employees to click a link and enter their credentials. Which type of social engineering attack is this?
⚠ Common exam trap
Cisco often tests the distinction between phishing (mass, untargeted) and spear phishing (targeted), so the trap here is that candidates may confuse the generic email to all employees with a targeted attack, leading them to incorrectly choose spear phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
B is correct because the attack uses email as the delivery vector to trick recipients into revealing credentials, which is the classic definition of phishing. Phishing is a broad category of social engineering that employs deceptive electronic communications (typically email) to steal sensitive information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing is voice-based social engineering conducted over telephone calls, whereas this attack arrives by email with a credential-harvesting link. It is tempting because both impersonate IT and seek credentials, but vishing would be the correct classification if the attacker telephoned employees directly.
- ✓
Phishing
Why this is correct
Phishing fits because the attacker uses a fraudulent email impersonating the IT department to trick employees into revealing credentials via a deceptive link. This satisfies the scenario's defining constraint: mass, electronic, credential-harvesting deception. Unlike spear phishing, it is not individually researched, and unlike vishing or smishing, the channel is email, matching the stem exactly.
- ✗
Pretexting
Why it's wrong here
Pretexting is a fabricated scenario to extract information, typically through conversation; here the mechanism is a credential-harvesting link in a mass email, which is phishing. Pretexting is tempting because impersonating IT is a pretext, but it would be the answer if the attacker engaged victims in dialogue to obtain data.
- ✗
Spear phishing
Why it's wrong here
The email is generic, sent to employees at large, so it is phishing or mass phishing rather than spear phishing. Spear phishing is tempting because it also impersonates a trusted party, but it targets a specific, researched individual or small group with tailored detail, which the stem does not describe.
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.