5. A user receives an unexpected text message containing a link to reset an expired password. Which of the following social engineering attacks is taking place?
Answer: D
Smishing is taking place in this scenario.
The user is experiencing smishing, which is a type of social engineering attack that involves fraudulent text messages aimed at tricking individuals into revealing personal information or clicking on malicious links.
A) Vishing
Vishing, or voice phishing, involves phone calls rather than text messages. This option is incorrect as the scenario specifically describes a text message, making vishing irrelevant to this particular case.
B) Spear phishing
Spear phishing targets specific individuals or organizations through personalized emails to gain sensitive information. However, this attack is typically conducted via email rather than text message, which makes it an unsuitable choice for the situation described.
C) Whaling
Whaling is a form of phishing that targets high-profile individuals such as executives. While it involves fraudulent attempts to obtain sensitive information, it is generally conducted through email and specifically aimed at high-value targets, making it not applicable to the text-based scenario provided.
D) Smishing
Smishing is the correct answer as it refers to phishing attempts via SMS text messages. In this case, the unexpected text message containing a link to reset an expired password is characteristic of this type of social engineering attack, as it seeks to deceive the user into clicking on a potentially harmful link.
Conclusion
Smishing is the definitive answer because it directly relates to the use of text messages for fraudulent purposes. The other options, while related to phishing tactics, do not align with the medium (text message) or the nature of the attack depicted in the scenario, reinforcing that smishing is the accurate classification of the attack described.