Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?

⚠ Common exam trap

The trap is conflating the attack method (social engineering) with its consequence (unauthorised access) — candidates pick the outcome category instead of the technique category.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Social engineering

Social engineering is the category of incident where an attacker manipulates a person into divulging confidential information such as login credentials, typically via phishing or pretexting. A fraudulent email tricking an employee into revealing credentials is the textbook definition of social engineering, which exploits human trust rather than technical vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Social engineering

    Why this is correct

    Social engineering manipulates people into divulging confidential information; phishing emails impersonating trusted entities are its classic vector. The fraudulent email tricking an employee into revealing credentials is precisely this category, distinguishing it from technical exploits such as malware or network attacks.

  • ✗

    Malware

    Why it's wrong here

    Phishing, not malware, describes deceiving an employee into disclosing credentials via a fraudulent email; malware is malicious code executed on a system. Malware would be the correct category if the email carried a malicious attachment or link that installed software, rather than harvesting credentials through social engineering.

  • ✗

    Unauthorised access

    Why it's wrong here

    Unauthorised access covers an attacker gaining entry to systems or data, but the credential theft here occurs through social engineering before any access is attempted. It fits scenarios where valid credentials are used to breach resources, not the phishing email that harvests them.

  • ✗

    Denial of service

    Why it's wrong here

    Denial of service concerns exhausting resources to make a system unavailable, which phishing for credentials does not do. It suits volumetric flooding, resource-exhaustion or amplification attacks, where availability, not confidentiality, is the target of the incident.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.