220-1102 Security Practice Question
A help desk technician receives a call from an employee who says they just received a phone call from someone claiming to be from the company's IT department. The caller stated there was a security breach and needed the employee's password to 'verify their account.' The employee did not provide the password but is now concerned. Which of the following BEST describes this type of social engineering attack, and what should the technician advise the employee to do NEXT?
⚠ Common exam trap
Candidates often confuse the attack type (vishing vs. phishing) and prioritizing a reactive password change over the correct incident response step of reporting to the security team.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
This is a vishing attack; the employee should report the incident to the security team and not call the number back.
The attack is vishing (voice phishing), where the attacker uses a phone call to trick the victim into revealing sensitive information. The employee should report the incident to the security team to initiate an investigation and should not call the number back, as that could lead to further social engineering or a premium-rate number scam.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
This is a vishing attack; the employee should change their password immediately and report the incident to the security team.
Why it's wrong here
The label 'vishing' is correct, but the prescribed action is misordered. Changing a password is only warranted if the employee actually disclosed credentials, which this scenario does not state; premature changes can lock the employee out of systems and create unnecessary help desk tickets. The correct first step is to report the incident to the security team, who can assess the exposure and direct a password change only if needed.
- ✗
This is a phishing attack; the employee should ignore the call and delete the caller's number from their phone.
Why it's wrong here
This response misclassifies the attack: vishing, not phishing, is the term for voice-based social engineering. More critically, deleting the caller's number destroys potentially useful evidence and does nothing to protect other employees from the same attempted attack. The employee should preserve the number and immediately report the attempt to the security team so that the call can be traced and a wider alert can be issued; ignoring it leaves the organization vulnerable.
- ✓
This is a vishing attack; the employee should report the incident to the security team and not call the number back.
Why this is correct
Vishing is a social engineering technique conducted over the phone, often using spoofed caller ID to impersonate legitimate entities. By reporting the incident, the employee enables the security team to analyze the attack vector, block the source, and inform the rest of the organization. The employee should not call back because that could confirm the line is active, extend the interaction, or provide additional opportunities for manipulation. Reporting is the single most important step in mitigating the threat.
- ✗
This is a whaling attack; the employee should call the company's official IT support number to verify the caller's identity.
Why it's wrong here
Whaling is a highly targeted form of phishing aimed at senior executives like the CEO, not typical general employees. Even though verifying a suspicious caller through official IT support is a sensible defensive habit, it is not the priority here; the employee should first report the incident to the security team. Calling IT support may be appropriate later, but the organization needs immediate knowledge of the attack. Therefore, this response both misidentifies the attack type and delays the critical reporting step.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user reports receiving a phone call from someone claiming to be from the company's help desk. The caller stated that there was a critical security issue and asked the user to provide their domain password to perform an emergency reset. The user complied. Which type of social engineering attack is this?
medium- A.Phishing
- ✓ B.Vishing
- C.SMiShing
- D.Tailgating
Why B: This is a vishing (voice phishing) attack because the social engineering was conducted over a phone call, where the attacker impersonated a help desk technician to trick the user into revealing their domain password. Unlike phishing (email) or SMiShing (SMS), vishing specifically uses voice communication to exploit human trust and urgency.
Variation 2. A user reports receiving a phone call from someone claiming to be from the IT department. The caller asks the user to install a remote access tool to help fix a network issue. The user complies. Later, the technician discovers that the remote access tool was used to install malware. Which type of social engineering attack is this?
hard- ✓ A.Vishing
- B.Pretexting
- C.Baiting
- D.Quid pro quo
Why A: Vishing (voice phishing) is a social engineering attack conducted over the phone. In this scenario, the attacker impersonated IT support to trick the user into installing a remote access tool, which was then used to deploy malware. The use of a phone call to elicit a security-compromising action is the hallmark of vishing.
Variation 3. A technician receives a phone call from someone who claims to be from the company's IT security team. The caller states that there is an urgent audit and asks the technician to provide their domain password to verify their identity. The technician provides the password. Which type of social engineering attack is this?
medium- A.Phishing
- ✓ B.Vishing
- C.Smishing
- D.Tailgating
Why B: B is correct because vishing (voice phishing) is a social engineering attack conducted over voice communication, such as a phone call, where the attacker impersonates a legitimate entity to trick the victim into revealing sensitive information. In this scenario, the technician received a phone call from someone claiming to be from the IT security team and was asked to provide their domain password, which is a classic vishing technique.
Variation 4. A user reports that they received a phone call from someone claiming to be from the company's IT help desk. The caller stated there was a security issue and requested the user's login credentials and a multi-factor authentication (MFA) code. The user provided the information. Which of the following should the technician do FIRST as part of the incident response?
medium- ✓ A.Disable the user's account and force a password reset
- B.Enable full disk encryption on the user's workstation
- C.Run a full antivirus scan on the user's workstation
- D.Check the domain controller logs for any evidence of lateral movement
Why A: The correct first step is to disable the user's account and force a password reset because the user has already compromised their credentials and MFA code, giving the attacker immediate access. This aligns with the NIST SP 800-61 incident response framework's containment phase, which prioritizes stopping further unauthorized access before any other action. By disabling the account, you prevent the attacker from using the stolen credentials to authenticate to any network resources, including VPN, email, or domain services.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.