Home > Glossary > CompTIA PenTest+ > Phishing

📖 What is Phishing?

Phishing is a social engineering attack where the attacker sends fraudulent messages designed to trick a person into revealing sensitive information or deploying malware. These messages often mimic trusted entities and create a sense of urgency to provoke a quick, unplanned response.

🥋 Sensei Says:

"Phishing is the most common initial access vector. Look for indicators like mismatched URLs and urgent language in exam scenarios."

📚 Certification: CompTIA PenTest+ (PT0-002)

🔑 What are the Key Concepts of Phishing?

  • Spear Phishing involves highly targeted attacks using OSINT to customize messages for specific individuals, increasing the likelihood of success over generic campaigns.
  • Whaling is a specialized form of spear phishing that targets high-profile executives to steal sensitive corporate data or authorize fraudulent financial transactions.
  • Vishing and Smishing extend phishing to voice calls and SMS messages, bypassing traditional email security filters to reach targets on mobile devices.
  • Payload delivery often utilizes malicious attachments with macros or links to credential harvesting sites to establish initial access into the target network.
  • Social engineering triggers like urgency, authority, and fear are used to manipulate victims into bypassing security protocols and acting without thinking.

🎯 How does Phishing appear on the PT0-002 Exam?

You may be asked to determine the most effective phishing method after performing OSINT on a specific target, requiring you to choose spear phishing over a generic campaign.

A scenario might describe an attacker sending SMS messages to employees regarding a password reset; you will need to identify this specific technique as Smishing.

Expect questions where you must analyze a provided email or URL to identify indicators of phishing, such as typosquatting or mismatched sender addresses.

❓ Frequently Asked Questions

What is the primary difference between phishing and spear phishing in a penetration test?

Phishing is a broad, 'spray-and-pray' approach targeting a large group. Spear phishing is a precision attack using specific details about the target, making it significantly more effective for bypassing security awareness.


How do attackers typically bypass email filters during a phishing simulation?

Attackers often use URL shortening, host malicious content on trusted cloud platforms like AWS or Azure, or employ homograph attacks using visually similar characters in the domain name.

Related Terms from CompTIA PenTest+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Phishing? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium