Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

A user receives an email that appears to be from their bank, asking them to click a link and verify their account details. The user notices the sender's email address is slightly misspelled. Which type of threat is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

Phishing is a social engineering attack where attackers send fraudulent emails to steal sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rootkit

    Why it's wrong here

    A rootkit hides deep in the operating system to maintain privileged, persistent access, so it cannot be delivered by a deceptive email link alone. It is tempting because rootkits also involve attacker access, but they are the right answer when malware conceals itself in kernel or firmware components, not when spoofing a sender's address.

  • ✓

    Phishing

    Why this is correct

    Phishing impersonates a trusted entity by email to trick the recipient into clicking a link and surrendering credentials. The misspelled sender address is the classic spoofing indicator, distinguishing it from malware, which requires execution, or social engineering conducted through other channels.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is a physical social-engineering technique where an attacker follows an authorised person through a secured door; it involves no email, link or spoofed sender address. It would be correct if the scenario described someone entering a restricted building without presenting their own credentials.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware encrypts files and demands payment, so it describes the payload rather than the deceptive email itself. It would be the correct answer if the stem described files becoming inaccessible with a payment demand, not a misspelled sender address requesting credential verification.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.