A user receives a text message (SMS) claiming to be from their bank, asking them to click a link and verify their account due to suspicious activity. This attack technique is BEST described as:
- A.Spear phishing via email
- B.Vishing (voice phishing)
- C.Smishing (SMS phishing)
- D.Pharming via DNS manipulation
Why C is correct
Smishing is phishing conducted via SMS/text messages. The attacker crafts an urgent, legitimate-appearing message and includes a malicious link. Vishing is phishing via voice calls (phone calls). Spear phishing is targeted email-based phishing aimed at a specific individual. Pharming redirects users to fake sites by poisoning DNS or modifying the hosts file - it does not use SMS. Smishing exploits the perception that SMS is more trustworthy than email, and users often click links in texts without scrutinizing them as carefully as email links.
Know someone studying for Network Fundamentals? Send them this one.