mediumMultiple ChoiceObjective-mapped
220-1202 Practice Question: A customer complains that their computer is…
A customer complains that their computer is running slowly and they keep seeing pop-ups offering free antivirus software. They admit they clicked 'OK' on one pop-up. Which type of social engineering attack has likely occurred?
⚠ Common exam trap
CompTIA often tests the distinction between phishing and baiting by presenting a scenario where a user is tricked by a free offer or physical media (like a USB drive), leading candidates to mistakenly choose phishing because both involve deception, but baiting specifically relies on the promise of a reward or free item.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Baiting
Aiting. In this scenario, the user clicked 'OK' on a pop-up offering free antivirus software, which is a classic baiting attack. Baiting lures victims with a false promise (e.g., free software) to trick them into executing malware or revealing credentials. Unlike phishing, which typically uses deceptive emails or websites to steal sensitive information, baiting relies on the allure of a free item or service to trigger a malicious download.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering technique that primarily involves sending fraudulent communications, typically via email or text message (smishing), or directing users to fake websites. The attacker's objective is to deceive recipients into revealing sensitive information, such as login credentials, credit card numbers, or other personal data, by impersonating a trustworthy entity. This method relies on urgency or fear to prompt a user to click a malicious link or open an infected attachment, rather than offering free software through a pop-up.
- ✓
Baiting
Why this is correct
Baiting is a social engineering attack that leverages a user's curiosity or greed by offering something desirable, such as "free" software, music, or a game, often advertised through a deceptive pop-up or left on a physical medium like a USB drive. The enticing offer serves as "bait" to trick the victim into installing or executing malware on their system. In this scenario, a pop-up offering "free antivirus" to a user with a slow computer directly aligns with baiting's modus operandi of exploiting a perceived need with a malicious solution.
- ✗
Pretexting
Why it's wrong here
Pretexting is a sophisticated social engineering technique where an attacker invents a believable, fabricated scenario (a "pretext") to manipulate a target into divulging specific information or performing an action. This often involves extensive research to create a convincing backstory, such as impersonating an IT support technician, a bank representative, or a government official, to gain trust and extract sensitive data through a series of questions. Unlike baiting, pretexting focuses on a constructed narrative and direct interaction to gather information, not a simple offer of free software via a pop-up.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is a low-tech social engineering method where an attacker directly observes a victim's screen or keyboard input from a close proximity to steal sensitive information. This passive form of information gathering typically occurs in public or semi-public spaces, such as cafes, airports, or offices, where an attacker can discreetly look over someone's shoulder to capture passwords, PINs, or other confidential data. It does not involve any digital interaction or pop-ups; rather, it relies solely on visual observation.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.