Courseiva
mediumMultiple ChoiceObjective-mapped

220-1202 Practice Question: That they clicked a link in a text message that…

A user reports that they clicked a link in a text message that appeared to be from their bank, warning of suspicious activity. The link led to a realistic-looking login page, but the user realized it was fake after entering their credentials. What type of social engineering attack is this?

⚠ Common exam trap

The CompTIA A+ exam often tests the distinction between smishing and vishing by focusing on the delivery method (SMS vs. voice), so candidates mistakenly choose vishing when they see 'text message' but focus on the 'warning of suspicious activity' pretext rather than the medium.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing

Smishing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) containing a link to a fraudulent website. The user received the message on their mobile device, clicked the link, and entered credentials on a fake login page, which is the hallmark of smishing. Unlike vishing (voice phishing), this attack uses text-based messaging to deliver the malicious link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vishing

    Why it's wrong here

    Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack conducted exclusively over telephone calls. Attackers use deceptive voice messages or live conversations to trick individuals into divulging sensitive information, such as bank account details, credit card numbers, or login credentials, by impersonating legitimate entities. Since the user in the question clicked a link in a text message, rather than interacting via a voice call, vishing is not the correct term for this specific attack vector.

  • Smishing

    Why this is correct

    Smishing is a specific form of phishing that leverages Short Message Service (SMS), commonly known as text messages, to deliver malicious links or solicit sensitive information. In a smishing attack, users receive a deceptive text message, often impersonating a legitimate entity like a bank or delivery service, which prompts them to click a fraudulent link. This link typically leads to a fake website designed to capture credentials or install malware, directly matching the scenario where a user clicked a link in a text message.

  • Pharming

    Why it's wrong here

    Pharming is a cyberattack that redirects users from legitimate websites to fraudulent ones without their explicit knowledge or interaction, often by manipulating Domain Name System (DNS) resolution or modifying local host files. Unlike phishing, pharming does not require the user to click a malicious link in an email or text message; instead, the redirection occurs automatically when the user attempts to access a legitimate site. The scenario described, where the user actively clicked a link, indicates an explicit user interaction not characteristic of pharming's passive redirection.

  • Pretexting

    Why it's wrong here

    Pretexting is a social engineering technique where an attacker creates a fabricated scenario, or "pretext," to manipulate a victim into divulging information or performing an action. This often involves impersonating someone in authority or a trusted individual to gain the victim's confidence through a convincing story, typically over the phone or in person. While a text message might be part of a broader pretexting scheme, the core of pretexting is the elaborate narrative and deception to extract information, whereas the question specifically highlights clicking a malicious link in a text message as the primary attack vector.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.