Courseiva
mediumMultiple Choice

220-1202 Practice Question: That they received a voicemail from the company's…

A user reports that they received a voicemail from the company's HR director asking them to call back a number to verify their account details for payroll. The user is suspicious because the HR director is on vacation. What type of social engineering attack is this?

⚠ Common exam trap

The key differentiator between vishing and pretexting is the communication channel—vishing specifically involves voice (phone/voicemail), while pretexting can occur via any medium (email, in-person, etc.).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

Vishing (voice phishing) is the correct classification because the attack uses a phone call—specifically a voicemail—to trick the user into calling back and divulging sensitive payroll information. Unlike phishing via email or SMS, vishing exploits voice communication channels to bypass text-based security filters and create a false sense of urgency or authority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Smishing

    Why it's wrong here

    Smishing delivers fraudulent text messages to mobile phones; this attack arrives as a voicemail, making it vishing. Smishing would be the answer if the HR impersonation arrived via SMS with a malicious link, rather than an audio message requesting a phone callback.

  • ✓

    Vishing

    Why this is correct

    Vishing uses voice communication, here a phone call and voicemail, to manipulate the target into disclosing account details. The callback number and payroll pretext exploit trust in the HR director, matching the stem's voice-channel social engineering scenario rather than phishing or smishing.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting involves inventing a scenario to extract information, typically through a fabricated story delivered in live conversation. Here the attack is a voicemail with a callback number, which is vishing. Pretexting would be the answer if the caller posed as HR directly and manipulated the user verbally.

  • ✗

    Pharming

    Why it's wrong here

    Pharming redirects web traffic to fraudulent sites via DNS poisoning or hosts-file manipulation; no web browsing occurs here. The voicemail with a callback number is vishing. Pharming would be correct if the user typed the payroll URL and was silently redirected to a credential-harvesting clone.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.