mediumMultiple ChoiceObjective-mapped
220-1202 Practice Question: Receiving a phone call from someone claiming to…
A user reports receiving a phone call from someone claiming to be from 'Microsoft Support' saying their computer has a virus and asking for remote access to fix it. The user did not grant access. What type of attack was attempted?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
This is a vishing (voice phishing) attack, a social engineering technique where the attacker uses phone calls to trick victims into providing sensitive information or remote access. Legitimate companies like Microsoft do not make unsolicited support calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a broad category of social engineering attacks where attackers attempt to trick individuals into revealing sensitive information or performing actions by impersonating a trustworthy entity. While it encompasses various methods, the term "phishing" most commonly refers to attacks conducted via email, often involving malicious links or attachments. The key distinction here is the primary communication channel, which in its most common form, is not a phone call.
- ✓
Vishing
Why this is correct
Vishing, a portmanteau of "voice" and "phishing," is a specific type of social engineering attack that leverages telephone calls to manipulate individuals. Attackers often impersonate legitimate entities like banks, technical support, or government agencies to trick victims into divulging personal data, financial information, or granting remote access to their systems. This method relies on the perceived urgency and directness of a live phone conversation to bypass typical digital security measures.
- ✗
Smishing
Why it's wrong here
Smishing is a form of phishing that specifically utilizes SMS (Short Message Service) text messages as its attack vector. Attackers send deceptive text messages, often containing malicious links or requests for personal information, by impersonating trusted organizations or services. The defining characteristic of smishing is its exclusive reliance on the text messaging platform, which is distinct from a live voice call or email.
- ✗
Pretexting
Why it's wrong here
Pretexting is a social engineering technique where an attacker creates an elaborate, fabricated scenario (a "pretext") to gain trust and extract information from a victim. While it can be delivered through various communication channels, including phone calls, pretexting describes the *method* of deception—the convincing false story—rather than the *medium* of delivery. The question specifically asks for the term describing a phone call attack, making vishing the more precise answer for the communication channel used.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.