Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A help desk technician receives a call from a user who received an email with an attachment labeled 'Invoice_2024.exe'. The user opened the attachment, but nothing appeared to happen. The email appeared to come from a known vendor, but the sender's email address contains misspellings. Which of the following BEST describes this type of attack, and what should the technician advise the user to do NEXT?

⚠ Common exam trap

Candidates often choose 'Spear phishing' because the email was targeted at a known vendor, but they overlook that the user already opened the attachment, making 'report the incident' the critical next step rather than just deleting the email.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing – advise the user to report the incident to the security team

The email with a malicious executable attachment that appears to come from a known vendor but has a misspelled sender address is a classic phishing attempt. Because the attack was specifically targeted at a known vendor relationship, it qualifies as spear phishing, but the question's answer options treat 'Phishing' as the broader category that includes spear phishing. The user opened the attachment, which likely executed malware, so the immediate next step is to report the incident to the security team so they can contain the threat and investigate the compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spear phishing – advise the user to delete the email and ignore it

    Why it's wrong here

    Spear phishing typically uses personalized details (e.g., your name, role, or known contacts) to trick a specific target, but this email relied on a generic invoice and a misspelled address—classic signs of a broad, untargeted phishing campaign. More critically, telling the user to simply delete the email after they have already opened the malicious attachment is dangerously insufficient: the executable may have already run, potentially installing malware or establishing persistence. The proper response is containment and investigation, not deletion.

  • ✓

    Phishing – advise the user to report the incident to the security team

    Why this is correct

    This is a textbook phishing email because it uses a generic lure (an invoice) and a malicious executable attachment to trick the user into running malware. Since the user already opened the attachment, the system may be compromised, so the incident must be immediately reported to the security team, who can quarantine the host, collect forensic evidence, and remediate any infection. Simply deleting the email would not undo any damage already done, and forwarding it without guidance could spread the threat or destroy evidence.

  • ✗

    Vishing – advise the user to ignore the message since it is not a phone call

    Why it's wrong here

    Vishing (voice phishing) is performed over telephone or VoIP systems, where an attacker spoofs a caller ID and uses social engineering to extract sensitive information directly from the target. This attack arrived via email and used an executable attachment, so it is categorically not vishing—it is an email-borne phishing attempt. Advising the user to ignore the message because it is not a phone call also fails to address the fact that the attachment was already opened, leaving the system potentially infected and in need of a security response.

  • ✗

    Pretexting – advise the user to forward the email to IT for verification

    Why it's wrong here

    Pretexting involves creating a fabricated scenario to steal information, but the attack here relies on a malicious attachment, not on building a false pretext. Forwarding to IT may be part of reporting, but the best immediate action is to report to the security team, not just forward.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.