Courseiva
mediumMatchingObjective-mapped

CS0-003 Match each attack type to its description. Practice Question

Match each attack type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Deceptive email to steal credentials

Malware that encrypts data for ransom

Overwhelming a service with traffic

Injecting malicious SQL queries

Intercepting communication between parties

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing: A mass email attack targeting many users

Correct matches: Phishing (mass email), Spear phishing (targeted email), Whaling (targeting executives). Common confusions: Vishing is voice, Smishing is SMS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing: A mass email attack targeting many users

    Why this is correct

    Phishing is a broad, untargeted social engineering attack that sends mass emails to thousands of recipients, impersonating trusted entities like banks or IT departments. The lure uses generic language and a call-to-action—such as 'verify your account'—to trick victims into clicking malicious links or revealing credentials. Because it relies on volume rather than personalization, even a low success rate yields many compromised accounts.

  • Spear phishing: A targeted email attack on a specific individual

    Why this is correct

    Spear phishing is a personalized form of email attack where the attacker researches a specific individual—using LinkedIn, corporate directories, or leaked data—and crafts a message that includes real names, job roles, or internal jargon. This customization bypasses automated filters and increases the target's trust, making it far more likely to succeed than generic phishing. Unlike mass phishing, spear phishing requires time and effort but yields a higher payoff per target.

  • Whaling: A spear phishing attack targeting high-level executives

    Why this is correct

    Whaling is a spear phishing attack specifically aimed at high-level executives such as CEOs, CFOs, or other C-suite personnel who have extensive access to financial assets and sensitive corporate data. The lures are often crafted around business-critical topics like legal subpoenas, mergers, or urgent wire transfers, exploiting the executive's authority and typically low level of cyber awareness. A single successful whaling attack can lead to massive financial losses, as seen in CEO fraud or business email compromise (BEC) scams.

  • Vishing: Phishing through social media messages

    Why it's wrong here

    This description is incorrect because vishing—voice phishing—uses telephone calls or Voice over IP (VoIP) to deceive victims, not social media messages. An attacker posing as a bank agent or tax official will call the target and pressure them into revealing sensitive information like PINs or one-time passwords. Social media phishing is a separate variant that occurs over platforms like LinkedIn, Facebook, or Twitter, sometimes called angler phishing.

  • Smishing: Voice phishing using phone calls

    Why it's wrong here

    This description is wrong because smishing (SMS phishing) uses text messages sent via the Short Message Service (SMS) to deliver malicious links or solicit personal data, not voice calls. A typical smishing attack might send a message like 'Your account has been suspended. Click here to reactivate' from an unrecognized number. Voice-based phishing is known as vishing, which uses phone calls or VoIP, so the two are distinct. Thus, smishing does not involve voice calls.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.