Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company's receptionist receives a phone call from someone claiming to be from the IT help desk. The caller states there is a critical security issue with the receptionist's computer and requests the receptionist's username and password to fix it remotely. Which type of social engineering attack is this?

⚠ Common exam trap

The 220-1102 exam often tests the distinction between pretexting and phishing by presenting a phone-based scenario, leading candidates to incorrectly choose 'phishing' because they associate credential theft with electronic methods rather than recognizing the fabricated story as the defining characteristic of pretexting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pretexting

Pretexting is a social engineering attack where the attacker fabricates a scenario (the pretext) to manipulate the target into divulging sensitive information. In this case, the caller falsely claims to be from the IT help desk and invents a critical security issue to trick the receptionist into providing their username and password. This is distinct from phishing, which typically uses electronic communication like email or fake websites to harvest credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing typically uses deceptive emails, text messages, or fraudulent websites that imitate legitimate services to trick victims into clicking malicious links, downloading attachments, or entering credentials on a fake login page. While voice-based social engineering exists as a subtype known as vishing, the scenario does not mention any electronic medium or malicious lure; the attack succeeds purely through an invented identity and a direct verbal request. Thus, classifying this as phishing would misclassify the specific technique used.

  • ✓

    Pretexting

    Why this is correct

    Pretexting is a social engineering technique in which the attacker creates a believable false scenario—here, an unsolicited phone call from someone claiming to be from IT—to lower the victim's defenses and elicit sensitive information, such as credentials or account details. The caller's fabricated identity and plausible justification of needing the information for 'verification' or 'maintenance' constitute the pretext, making this a textbook example. Unlike phishing, there is no fake email or website; the social manipulation occurs entirely through the direct conversation.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating, also known as piggybacking, is a physical security breach in which an unauthorized person gains entry to a restricted area by closely following an authorized employee through a door, turnstile, or gate that requires authentication. This attack exploits the natural human tendency to hold a door open for the next person and involves no phone call, verbal pretext, or request for information. Because the scenario described is a remote voice interaction with no physical access component, it cannot be considered tailgating.

  • ✗

    Baiting

    Why it's wrong here

    Baiting is a social engineering attack that offers a tempting lure—such as an infected USB drive left in a parking lot, a free movie download, or an advertisement promising a reward—to provoke the victim's curiosity or greed into performing an action that compromises security. The attacker typically relies on the physical device or a digital enticement to deliver the payload, whereas the phone call in this scenario extends no reward and offers no item, but instead uses a fabricated authority figure. Since there is no lure or physical object involved, baiting does not apply.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician receives a phone call from someone claiming to be from the company's help desk. The caller states there is a problem with the technician's account and asks for the technician's username and password to 'run a test'. Which type of social engineering attack is this?

medium
  • ✓ A.Pretexting
  • B.Phishing
  • C.Vishing
  • D.Shoulder surfing

Why A: This is a classic pretexting attack because the caller fabricates a scenario (claiming to be from the help desk and needing to 'run a test') to trick the technician into revealing sensitive credentials. Pretexting relies on creating a false identity or story to gain trust, which is exactly what happens when an attacker impersonates internal IT support. The attack is voice-based, but the core deception is the invented pretext, not the medium itself.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.