Skip to content
Exercises · Q9

Q.The school offers wireless facility (wifi) to the Computer Science students of Class XI. For communication, the network security staff of the school have a registered URL schoolwifi.edu. On 17 September 2017, the following email was mass distributed to all the Computer Science students of Class XI. The email claimed that the password of the students was about to expire. Instructions were given to go to URL to renew their password within 24 hours. [Email shown in the textbook — Subject: “Your Password will expire in 1 day”, to me. Body: “Dear Students, This email is meant to inform you that your SchoolWifi network password will expire in 24 hours. Please follow the link below to update your password. schoolwifii.edu/updatepassword Thank you Network security staff”]

a) Do you find any discrepancy in this email?
b) What will happen if the student will click on the given URL?
c) Is the email an example of cyber crime? If yes, then specify which type of cyber crime is it. Justify your answer.
Sikkim CbseNCERTSubjective· 4mImportance★★★★★
48% · 15/31 Questions
🔒 Locked · start free trial →

You're viewing a preview — the full solution, concept, methods & PYQ mapping are locked.

Start your 14-day free trial to unlock the full solution →

The email is a phishing attack: (a) the link's domain schoolwifii.edu (extra "i") differs from the school's registered schoolwifi.edu;

(b) the link leads to a fake page that harvests the student's password;

(c) yes — phishing / attempted identity theft, punishable under the IT Act.

The concept (phishing and identity theft). Phishing emails impersonate a trusted authority, invent urgency, and route victims to a look-alike URL where credentials are harvested. The forged domain is usually one character away from the real one — exactly what we see here.

a) Do you find any discrepancy in this email?

Yes, several:

  • The URL is wrong: the school's registered domain is schoolwifi.edu, but the email says schoolwifii.edu — an extra "i". A one-letter look-alike domain is the signature of phishing.
  • Manufactured urgency: "expires in 24 hours" pressures students to act before thinking.
  • Generic, unverifiable sender: addressed to "Dear Students" from unnamed "Network security staff", mass-mailed to everyone at once.

b) What will happen if the student clicks the given URL?

The link opens a counterfeit page designed to look like the school's password-update portal. When the student enters the current password (and perhaps a "new" one), those credentials go straight to the attacker. The attacker can then log into the student's school wifi/network account, misuse it in the student's name, and try the same password on the student's other accounts (many people reuse passwords). Malicious pages may also attempt to install malware.

c) Is the email an example of cyber crime? If yes, which type? …

Unlock everything free for 14 days

  • Full step-by-step solutions
  • Concept-first explanations
  • Methods, shortcuts & mistakes
  • PYQ mapping + timed mock tests

Full access for 14 days. No credit card required.