ITPEC FE Subject A October 2024 Question 27
ITPEC FE Subject A October 2024 — Question 27 of 60
Phishing email — identifying the defining characteristic of phishing attacks.
Phishing = fraudulent email impersonating a trusted entity to steal credentials/data by redirecting the victim to a fake site. The fake banking site is the classic delivery mechanism: user enters login/password → attacker captures it.
Why not others:
- (a) Pop-up ads = spam/adware, not phishing — no credential theft attempt
- (b) Intercepted and altered = MITM (Man-in-the-Middle) attack, different attack class
- (c) Auto-installs malware = drive-by download / trojan, not phishing — phishing relies on deception, not auto-execution
Key rule: Phishing = fake trusted site/entity → steal credentials. The link → fake site pattern is the textbook definition.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.