Courseiva
easyMultiple Choice

PT0-002 Practice Question: A penetration tester is performing a client-side…

A penetration tester is performing a client-side attack against a user. The tester sends an email with a malicious attachment that, when opened, executes a macro that downloads a payload. Which type of attack is this?

⚠ Common exam trap

It's easy for candidates to confuse spear phishing with generic phishing or social engineering categories like vishing/smishing, but the key differentiator is the use of a personalized email with a malicious attachment, not the delivery medium (voice or SMS).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spear phishing

Spear phishing is a targeted phishing attack where the attacker crafts a personalized email to a specific individual or organization, often including a malicious attachment. In this scenario, the email with a macro-enabled attachment that downloads a payload is a classic spear phishing technique, as it exploits human trust and social engineering to deliver malware. This contrasts with generic phishing, which casts a wide net, and the client-side attack vector relies on the user executing the macro.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Spear phishing

    Why this is correct

    Spear phishing is the correct choice because the scenario describes a client-side attack that targets a specific user through email with a malicious attachment. Unlike generic phishing, spear phishing leverages reconnaissance—such as the victim's name, role, or interests—to craft a highly convincing message, increasing the likelihood of the user opening the attachment. This direct, personalized email vector aligns perfectly with the definition of spear phishing.

  • ✗

    Vishing

    Why it's wrong here

    Vishing is incorrect because it relies on voice communication, typically through phone calls or VoIP, to deceive the target into revealing sensitive information or performing an action. It does not use email or attachments, and the attack vector is auditory, not file-based. While vishing can be a client-side attack, the scenario's explicit mention of a malicious attachment eliminates voice as the delivery mechanism.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is incorrect because it uses SMS or text messages as the attack vector, often with a link or a prompt to reply, rather than email with an attachment. The term 'smishing' is a portmanteau of 'SMS' and 'phishing,' and it exploits the trust people place in text messages. The scenario's email-based delivery with an attachment distinguishes it from smishing, which typically directs victims to a malicious website via a texted URL.

  • ✗

    Watering hole

    Why it's wrong here

    A watering hole attack is incorrect because it does not involve sending a direct message to the target. Instead, the attacker compromises a website that the target is known to visit, planting malware that infects the user's system when they browse the site. This method relies on the target to initiate the visit, whereas the scenario states a direct client-side attack, suggesting a proactive delivery like email.

Go deeper

Related to this question

About these practice questions

Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.