220-1102 Security Practice Question
A company's receptionist receives a phone call from someone claiming to be from the IT help desk. The caller states there is a critical security issue with the receptionist's computer and requests the receptionist's username and password to fix it remotely. Which type of social engineering attack is this?
⚠ Common exam trap
The 220-1102 exam often tests the distinction between pretexting and phishing by presenting a phone-based scenario, leading candidates to incorrectly choose 'phishing' because they associate credential theft with electronic methods rather than recognizing the fabricated story as the defining characteristic of pretexting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is a social engineering attack where the attacker fabricates a scenario (the pretext) to manipulate the target into divulging sensitive information. In this case, the caller falsely claims to be from the IT help desk and invents a critical security issue to trick the receptionist into providing their username and password. This is distinct from phishing, which typically uses electronic communication like email or fake websites to harvest credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing typically uses deceptive emails, text messages, or fraudulent websites that imitate legitimate services to trick victims into clicking malicious links, downloading attachments, or entering credentials on a fake login page. While voice-based social engineering exists as a subtype known as vishing, the scenario does not mention any electronic medium or malicious lure; the attack succeeds purely through an invented identity and a direct verbal request. Thus, classifying this as phishing would misclassify the specific technique used.
- ✓
Pretexting
Why this is correct
Pretexting is a social engineering technique in which the attacker creates a believable false scenario—here, an unsolicited phone call from someone claiming to be from IT—to lower the victim's defenses and elicit sensitive information, such as credentials or account details. The caller's fabricated identity and plausible justification of needing the information for 'verification' or 'maintenance' constitute the pretext, making this a textbook example. Unlike phishing, there is no fake email or website; the social manipulation occurs entirely through the direct conversation.
- ✗
Tailgating
Why it's wrong here
Tailgating, also known as piggybacking, is a physical security breach in which an unauthorized person gains entry to a restricted area by closely following an authorized employee through a door, turnstile, or gate that requires authentication. This attack exploits the natural human tendency to hold a door open for the next person and involves no phone call, verbal pretext, or request for information. Because the scenario described is a remote voice interaction with no physical access component, it cannot be considered tailgating.
- ✗
Baiting
Why it's wrong here
Baiting is a social engineering attack that offers a tempting lure—such as an infected USB drive left in a parking lot, a free movie download, or an advertisement promising a reward—to provoke the victim's curiosity or greed into performing an action that compromises security. The attacker typically relies on the physical device or a digital enticement to deliver the payload, whereas the phone call in this scenario extends no reward and offers no item, but instead uses a fabricated authority figure. Since there is no lure or physical object involved, baiting does not apply.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician receives a phone call from someone claiming to be from the company's help desk. The caller states there is a problem with the technician's account and asks for the technician's username and password to 'run a test'. Which type of social engineering attack is this?
medium- ✓ A.Pretexting
- B.Phishing
- C.Vishing
- D.Shoulder surfing
Why A: This is a classic pretexting attack because the caller fabricates a scenario (claiming to be from the help desk and needing to 'run a test') to trick the technician into revealing sensitive credentials. Pretexting relies on creating a false identity or story to gain trust, which is exactly what happens when an attacker impersonates internal IT support. The attack is voice-based, but the core deception is the invented pretext, not the medium itself.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.