Courseiva
mediumMultiple Choice

FC0-U71 Practice Question: An employee receives an email from 'IT Support'…

An employee receives an email from 'IT Support' asking for his password due to 'system maintenance'. This is an example of:

⚠ Common exam trap

A common mix-up: candidates confuse pretexting with phishing because both involve a fabricated story, but the exam specifically tests that phishing is the correct term when the attack is carried out via email, instant message, or other electronic communication, whereas pretexting is broader and often involves direct voice or in-person interaction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

Phishing is a social engineering attack where an attacker masquerades as a trusted entity (here, 'IT Support') to trick the victim into revealing sensitive information, such as a password. The email requesting credentials under the pretext of 'system maintenance' is a classic phishing technique, often executed via email (spear phishing if targeted). This directly matches the definition of phishing as an attempt to acquire sensitive data through deceptive electronic communication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Baiting

    Why it's wrong here

    Baiting offers something enticing, such as a malware-laden USB drive or download, to provoke a victim's curiosity; this email instead impersonates IT Support and requests credentials directly. Baiting is tempting as another social-engineering category, but no lure or infected medium is present here.

  • ✓

    Phishing

    Why this is correct

    The message impersonates IT Support and pressures the recipient into disclosing credentials, which is credential-harvesting social engineering delivered by email. Phishing is defined by exactly that deceptive lure, distinguishing it from vishing, smishing or pretexting conducted through other channels.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is physically following an authorised person through a secure door; this scenario is a written social-engineering message, not physical proximity. It is tempting because both are social-engineering techniques, but tailgating requires a physical access-control boundary, which email cannot cross.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting involves inventing a fabricated scenario to extract information, which this email does by posing as IT Support during maintenance. It is tempting because pretexting overlaps with phishing, but the question's credential-harvesting email is phishing; pretexting is the invented persona, not the delivery mechanism.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.