mediumMultiple Choice
220-1202 Practice Question: That they received a voicemail from the company's…
A user reports that they received a voicemail from the company's HR director asking them to call back a number to verify their account details for payroll. The user is suspicious because the HR director is on vacation. What type of social engineering attack is this?
⚠ Common exam trap
The key differentiator between vishing and pretexting is the communication channel—vishing specifically involves voice (phone/voicemail), while pretexting can occur via any medium (email, in-person, etc.).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
Vishing (voice phishing) is the correct classification because the attack uses a phone call—specifically a voicemail—to trick the user into calling back and divulging sensitive payroll information. Unlike phishing via email or SMS, vishing exploits voice communication channels to bypass text-based security filters and create a false sense of urgency or authority.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smishing
Why it's wrong here
Smishing delivers fraudulent text messages to mobile phones; this attack arrives as a voicemail, making it vishing. Smishing would be the answer if the HR impersonation arrived via SMS with a malicious link, rather than an audio message requesting a phone callback.
- ✓
Vishing
Why this is correct
Vishing uses voice communication, here a phone call and voicemail, to manipulate the target into disclosing account details. The callback number and payroll pretext exploit trust in the HR director, matching the stem's voice-channel social engineering scenario rather than phishing or smishing.
- ✗
Pretexting
Why it's wrong here
Pretexting involves inventing a scenario to extract information, typically through a fabricated story delivered in live conversation. Here the attack is a voicemail with a callback number, which is vishing. Pretexting would be the answer if the caller posed as HR directly and manipulated the user verbally.
- ✗
Pharming
Why it's wrong here
Pharming redirects web traffic to fraudulent sites via DNS poisoning or hosts-file manipulation; no web browsing occurs here. The voicemail with a callback number is vishing. Pharming would be correct if the user typed the payroll URL and was silently redirected to a credential-harvesting clone.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.