Courseiva
mediumMultiple Choice

220-1202 Practice Question: A user receives an email that appears to be from…

A user receives an email that appears to be from their bank, asking them to click a link and verify their account information due to 'suspicious activity.' The email address looks legitimate, but the link points to a different domain. What type of attack is this?

⚠ Common exam trap

CompTIA A+ often tests the distinction between generic phishing and targeted variants like spear phishing or whaling, and the trap here is that candidates see a legitimate-looking sender address and assume it's spear phishing, missing the broad, unsolicited nature of the attack.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

This is a classic phishing attack because the email uses social engineering to trick the user into clicking a link that leads to a fraudulent domain, even though the sender's address appears legitimate. Phishing is a broad category of social engineering where attackers impersonate a trusted entity to steal credentials or sensitive information, and the mismatched link is the key indicator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing targets a named individual using researched personal details, whereas this message is a generic bank lure sent without tailoring. It is tempting because spear phishing also spoofs trusted senders, and would be correct if the email addressed the recipient by name and referenced their actual account activity.

  • ✓

    Phishing

    Why this is correct

    Phishing deceives the recipient into clicking a link or divulging data by impersonating a trusted entity. The spoofed bank sender combined with a link resolving to an unrelated domain is the defining mechanism, distinguishing it from other social-engineering or technical attacks.

  • ✗

    Whaling

    Why it's wrong here

    Whaling specifically targets senior executives such as CEOs or CFOs, and nothing in the stem identifies the recipient as an executive. It is tempting because whaling also impersonates authority figures to trigger urgent action, and would be correct if a chief financial officer received a fraudulent payment request.

  • ✗

    Vishing

    Why it's wrong here

    Vishing is voice-based social engineering conducted over telephone calls, so no phone call occurs here; the lure arrives by email with a mismatched hyperlink. It is tempting because vishing also impersonates a bank to harvest credentials, and would be correct if the victim were telephoned by a fake fraud department instead.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.