ISC2 CC Security Operations Practice Question
An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?
⚠ Common exam trap
The trap is confusing phishing with other social engineering methods like tailgating or USB drops; candidates may pick tailgating if they focus on 'unknown sender' but miss that the attack vector is email.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
Phishing is a social engineering attack where an attacker sends a fraudulent email, often impersonating a trusted entity like the IT department, to trick the recipient into revealing sensitive information such as passwords. The scenario describes an email from an unknown sender claiming to be from IT and requesting a password, which is a classic phishing attempt. The other options involve physical or direct access tactics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing
Why this is correct
The message impersonates the IT department and pressures the recipient to disclose credentials urgently, which is phishing: fraudulent email harvesting sensitive data. It satisfies the stem's description, distinguishing it from vishing or pretexting conducted by other channels.
- ✗
Tailgating
Why it's wrong here
Tailgating is physical: an unauthorised person follows an employee through a secured door. This attack arrives by email and requests credentials, which is phishing. Tailgating would be the answer if the scenario described someone entering a building behind a badge-holder.
- ✗
USB drop attack
Why it's wrong here
A USB drop attack relies on planting infected removable media for a victim to plug in. Nothing physical is involved here; the email itself solicits the password, making it phishing. USB drops fit scenarios where found drives are inserted into company machines.
- ✗
Piggybacking
Why it's wrong here
Piggybacking is physical entry: an attacker accompanies an authorised person through a door with their consent or knowledge. This scenario is an email requesting credentials, which is phishing. Piggybacking would apply if someone talked their way past reception into a server room.
Go deeper
Related to this question
Learn chapter
Physical Access Controls
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.