CPA · Question 21 · Area II: Security
A penetration tester is hired to assess a company's external security. The tester sends a deceptive email to the HR department claiming to be an applicant, with a malicious attachment designed to harvest credentials. This type of attack is best classified as:
Answer options:
SQL Injection
Spear Phishing
Cross-Site Scripting (XSS)
Man-in-the-Middle
82 questions · hints · full answers · grading