mediumMultiple SelectObjective-mapped
ISC2 CC Practice Question: Which TWO of the following are common indicators…
Which TWO of the following are common indicators of a phishing email? (Select TWO.)
⚠ Common exam trap
ISC2 often tests the distinction between technical indicators (e.g., file extensions, headers) and behavioral indicators (e.g., urgency, domain spoofing), and the trap here is that candidates mistake common email features like high-importance flags or bulk addressing as phishing indicators when they are not inherently suspicious.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email contains a sense of urgency, such as 'Your account will be closed.'
Phishing emails commonly exploit urgency to bypass rational decision-making. Attackers use phrases like 'Your account will be closed' to pressure recipients into clicking malicious links or providing credentials without verifying the source. This social engineering tactic is a hallmark of phishing campaigns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The email contains an attachment with a .txt extension
Why it's wrong here
.txt files are generally safe; phishing often uses .exe, .docm, or .zip.
- ✓
The email contains a sense of urgency, such as 'Your account will be closed.'
Why this is correct
Urgency is a common social engineering tactic.
- ✗
The email has a high-importance flag set by the sender
Why it's wrong here
Importance flags are not reliable indicators; they can be set by anyone.
- ✗
The email is sent to multiple recipients in the 'To' field
Why it's wrong here
Legitimate emails can also be sent to multiple recipients; not a reliable indicator.
- ✓
The sender's email address is similar but not identical to a legitimate domain
Why this is correct
Spoofed or lookalike domains are typical in phishing.
Go deeper
Related to this question
Learn chapter
Wireless and Remote Access Security
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 976 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.