Which of the following is a type of cyber attack that involves tricking users into revealing sensitive information?
- A.Phishing attack
- B.SQL injection attack
- C.DoS attack
- D.None of the above
Show answer
Correct answer: A. Phishing attack
Explanation
The correct answer is A, phishing attack. Phishing sends a message that looks as if it came from a bank, an employer or a government office, and asks the reader to confirm a password, a card number or a one-time password on a page that belongs to the attacker; the target of the attack is the person, not the machine, which is why it is classed as social engineering. Option B is wrong because SQL injection puts database commands into a web form to make the server reveal stored data; the user is not tricked at all. Option C is wrong because a denial of service attack floods a server with requests so that genuine users cannot reach it, which harms availability and steals nothing. Option D is wrong because option A is correct. Remember the family: spear phishing on one person, whaling on an executive, vishing by call, smishing by message.