mediumMultiple Choice
220-1202 Practice Question: A user receives an email with a link that appears…
A user receives an email with a link that appears to be from their bank, asking them to verify their account. The link leads to a page that looks exactly like the bank's login page. What type of attack is this?
⚠ Common exam trap
CompTIA often tests the distinction between phishing and man-in-the-middle attacks by presenting a scenario where the user is tricked into voluntarily providing credentials on a fake site, which is phishing, not an active interception of network traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A phishing attack.
This scenario describes a phishing attack, where the attacker sends a deceptive email impersonating a trusted entity (the bank) to trick the user into clicking a malicious link. The link leads to a fraudulent website that mimics the legitimate bank login page, designed to capture the user's credentials. Phishing exploits social engineering rather than technical vulnerabilities, relying on the user's trust and inattention to detail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A man-in-the-middle attack.
Why it's wrong here
A man-in-the-middle attack intercepts and relays traffic between two parties who believe they communicate directly. This scenario involves no interception or relay; the user simply visits a counterfeit page. MitM would fit if an attacker proxied the genuine bank session to capture credentials.
- ✓
A phishing attack.
Why this is correct
Phishing deceives the recipient into trusting a spoofed message and surrendering credentials on a counterfeit login page. The lookalike bank page and the verification request satisfy the scenario's defining constraint: credential harvesting through social engineering rather than malware or network exploitation.
- ✗
A ransomware attack.
Why it's wrong here
Ransomware encrypts files and demands payment for decryption keys; nothing here encrypts or locks data. The email merely lures the user to a credential-harvesting page. Ransomware would be correct if the attachment or link installed encrypting malware that held the user's files hostage.
- ✗
A cross-site scripting (XSS) attack.
Why it's wrong here
XSS injects malicious scripts into websites; this scenario is a social engineering attempt via email.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.