Courseiva
easyMultiple Choice

Pretexting: Attacker Impersonates IT on Phone

A receptionist at a company receives a call from someone claiming to be from the IT department. The caller says they need her password to perform an urgent server update. The receptionist provides the password. What type of social engineering attack is this?

Quick Answer

The answer is pretexting. This is the correct choice because the attacker constructed a fabricated scenario—or pretext—by impersonating an IT staff member to create a false sense of urgency and authority, specifically requesting the receptionist’s password for a fake server update. On the CompTIA A+ Core 2 220-1202 exam, this scenario tests your ability to distinguish pretexting from other social engineering attacks like phishing or vishing; a common trap is confusing it with vishing, but vishing is voice-based phishing that typically uses fear or reward, whereas pretexting relies on building a believable role and story. A key memory tip is to think of the word “pretext” as a “pre-written script” the attacker follows to act out a part—here, the part of an IT technician.

⚠ Common exam trap

CompTIA often tests the distinction between pretexting and phishing by emphasizing that pretexting relies on a fabricated scenario (often via phone or in-person) rather than a technical lure or electronic message, so candidates mistakenly choose phishing when the attack vector is a voice call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pretexting

Pretexting is a social engineering attack where the attacker fabricates a scenario (the pretext) to manipulate the target into divulging sensitive information. In this case, the caller falsely claims to be from the IT department and invokes an urgent server update to trick the receptionist into revealing her password. This is not a technical exploit but a psychological manipulation that relies on the target's trust in authority and urgency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is physically following an authorised person through a secured door without their consent; no physical access or proximity occurs in a phone call. It is tempting because both are social engineering, and would be correct if the attacker had walked into the building behind an employee.

  • ✓

    Pretexting

    Why this is correct

    Pretexting fits because the caller fabricates an IT-department identity and an urgent server-update scenario to justify requesting credentials. This invented context, or pretext, exploits the receptionist's trust in authority and time pressure, satisfying the stem's constraint of a plausible false narrative used to extract the password.

  • ✗

    Phishing

    Why it's wrong here

    Phishing delivers a fraudulent message, typically email or a spoofed site, to harvest credentials; this attack used a live phone call, which is vishing. It is tempting because both impersonate a trusted party, and would be correct had the request arrived by email or text instead.

  • ✗

    Baiting

    Why it's wrong here

    Baiting leaves physical media such as infected USB drives for victims to plug in, exploiting curiosity. Here the caller verbally demanded credentials under an urgent pretext, which is pretexting (or vishing). Baiting would fit a scenario where a labelled USB stick is dropped in a car park.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on 220-1202

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician receives a call from someone claiming to be from the company's IT security team, asking for the administrator password to 'run a critical update.' The caller's voice sounds stressed and they mention a data breach. What should the technician do?

easy
  • A.Provide the password immediately to prevent a data breach.
  • ✓ B.Ask for a callback number and verify it against the company directory.
  • C.Ignore the call because IT never calls about updates.
  • D.Change the password and give them the new one.

Why B: It follows the principle of verifying identity through a trusted channel before disclosing sensitive information. The technician should ask for a callback number and cross-reference it against the company directory to ensure the caller is legitimate, as social engineering attacks often use urgency and impersonation to bypass security protocols.

Variation 2. A new employee is setting up their workstation and receives a phone call from someone claiming to be from the IT department. The caller says there is a critical security update and needs the employee's login credentials to install it remotely. What social engineering principle is the attacker primarily exploiting?

easy
  • A.Urgency
  • B.Scarcity
  • ✓ C.Authority
  • D.Social proof

Why C: The attacker is impersonating IT staff, which leverages the principle of authority. By claiming to be from the IT department, the attacker exploits the employee's tendency to comply with perceived organizational authority, especially regarding security updates. This is a classic social engineering tactic where the attacker uses a trusted role to bypass security protocols.

Variation 3. A technician is configuring a new employee's workstation. The employee mentions that a 'friendly IT guy' from the help desk called earlier and asked for their username and temporary password to 'pre-setup the account'. The employee provided the information. What should the technician do first?

medium
  • A.Proceed with the setup as planned, since the employee already provided the info.
  • ✓ B.Reset the employee's password and report the incident to the security team.
  • C.Call the help desk to verify if they made the call.
  • D.Tell the employee it was likely a test and to ignore it.

Why B: The employee has already fallen victim to a social engineering attack (phishing or vishing). The technician must immediately reset the compromised password to prevent unauthorized access and report the incident to the security team so they can investigate and mitigate further risk. This follows the principle of least privilege and incident response best practices for credential compromise.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.