Courseiva
Security Operations →easyMultiple Choice

ISC2 CC Security Operations Practice Question

An employee receives an email from an unknown sender claiming to be from the IT department, asking for their password to perform an urgent system update. What type of social engineering attack is this?

⚠ Common exam trap

The trap is confusing phishing with other social engineering methods like tailgating or USB drops; candidates may pick tailgating if they focus on 'unknown sender' but miss that the attack vector is email.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

Phishing is a social engineering attack where an attacker sends a fraudulent email, often impersonating a trusted entity like the IT department, to trick the recipient into revealing sensitive information such as passwords. The scenario describes an email from an unknown sender claiming to be from IT and requesting a password, which is a classic phishing attempt. The other options involve physical or direct access tactics.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Phishing

    Why this is correct

    The message impersonates the IT department and pressures the recipient to disclose credentials urgently, which is phishing: fraudulent email harvesting sensitive data. It satisfies the stem's description, distinguishing it from vishing or pretexting conducted by other channels.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is physical: an unauthorised person follows an employee through a secured door. This attack arrives by email and requests credentials, which is phishing. Tailgating would be the answer if the scenario described someone entering a building behind a badge-holder.

  • ✗

    USB drop attack

    Why it's wrong here

    A USB drop attack relies on planting infected removable media for a victim to plug in. Nothing physical is involved here; the email itself solicits the password, making it phishing. USB drops fit scenarios where found drives are inserted into company machines.

  • ✗

    Piggybacking

    Why it's wrong here

    Piggybacking is physical entry: an attacker accompanies an authorised person through a door with their consent or knowledge. This scenario is an email requesting credentials, which is phishing. Piggybacking would apply if someone talked their way past reception into a server room.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.