220-1102 Security Practice Question
A help desk technician receives a phone call from an individual who claims to be a representative from the company's primary software vendor. The caller states there is a critical security vulnerability in the software and requests the technician's administrative username and password to install an emergency patch immediately. The technician suspects social engineering. Which type of social engineering attack is being attempted?
⚠ Common exam trap
Candidates often confuse pretexting with phishing because both involve deception, but phishing specifically refers to electronic, often automated, attacks (email, SMS, web), whereas pretexting involves a live, interactive social interaction (phone call, in-person) where a fabricated story is the primary vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting. In this scenario, the caller fabricates a false identity (a representative from the software vendor) and invents a plausible scenario (a critical security vulnerability requiring an emergency patch) to trick the technician into divulging sensitive information. This is the hallmark of pretexting, where the attacker creates a fabricated story (pretext) to gain the victim's trust and obtain credentials or other data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Pretexting
Why this is correct
Pretexting is correct because the attacker invents a plausible scenario—here, a fake emergency or vendor crisis—to establish a false identity and gain the victim's trust. The phone call is a conversational, interactive vector that relies on manipulating the target's emotions or sense of urgency to extract confidential information. Unlike phishing, which typically uses digital messages, pretexting leverages a fabricated narrative and direct social interaction.
- ✗
Phishing
Why it's wrong here
Phishing is incorrect because it conventionally refers to mass-delivered fraudulent emails or text messages designed to lure victims into clicking malicious links or entering credentials on fake websites. Although phone-based 'vishing' is a form of phishing, the classic definition of phishing centers on electronic communication with a spoofed sender and a call-to-action. The question describes a direct phone call with a fabricated story, which is more precisely pretexting rather than the email/text-based phishing attack.
- ✗
Baiting
Why it's wrong here
Baiting is incorrect because it exploits curiosity or greed by offering an attractive lure, such as a free movie download, a prize, or a USB drive left in a parking lot. The attacker here does not offer any tangible incentive; instead, they request the victim's credentials under false pretenses. The core mechanism is not an enticing offer but a contrived emergency, placing it in the pretexting category.
- ✗
Tailgating
Why it's wrong here
Tailgating is incorrect because it is a physical security attack where an unauthorized person follows an authorized individual through a secured door or access point, often by pretending to be an employee or delivery person. The scenario in question involves no physical proximity or restricted-area access; it is a purely remote social engineering attempt conducted over the phone, so it does not match this physical attack vector.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.