Courseiva
mediumMultiple Choice

220-1102 Practice Question: A new employee receives an email that appears to…

A new employee receives an email that appears to be from the company's HR department, asking them to click a link to verify their direct deposit information for payroll. The email contains the company logo and looks professional. What is the most likely social engineering attack?

⚠ Common exam trap

The trap is that candidates may confuse phishing with whaling because both use email, but the key differentiator is the target: phishing is broad and untargeted, while whaling specifically targets high-level executives or individuals with privileged access. For example, an email targeting a CEO about a wire transfer is whaling, while an email targeting many employees about updating HR info is phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

Phishing is the correct answer because the attack uses a deceptive email that impersonates a legitimate entity (HR department) to trick the recipient into clicking a malicious link. This is a classic example of a broad, untargeted social engineering attack delivered via email, which is the defining characteristic of phishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Whaling

    Why it's wrong here

    The email targets a new employee, not an executive, so it fails the whaling criterion of singling out senior figures such as the CEO or CFO for high-value fraud. Whaling is tempting because it also impersonates authority and uses a plausible pretext, but it would be correct only if the recipient held an executive role.

  • ✓

    Phishing

    Why this is correct

    Phishing uses a spoofed, professional-looking email impersonating a trusted internal sender such as HR to trick the recipient into clicking a link and surrendering credentials or financial details. The direct deposit lure and forged branding match this attack precisely.

  • ✗

    Vishing

    Why it's wrong here

    Vishing uses voice communication such as phone calls or voicemail to manipulate victims, so it cannot describe an email-based lure. It is tempting because vishing is a genuine social engineering technique, and would be the correct answer if the employee had instead received a phone call from someone impersonating HR requesting payroll details.

  • ✗

    Shoulder surfing

    Why it's wrong here

    Shoulder surfing requires an attacker to observe credentials or data directly over the victim's shoulder, which no email link can accomplish. It is tempting because it is a genuine social engineering technique, and would be correct if the scenario described someone watching a colleague type payroll details in a public space.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.