mediumMultiple Choice
220-1102 Practice Question: A new employee receives an email that appears to…
A new employee receives an email that appears to be from the company's HR department, asking them to click a link to verify their direct deposit information for payroll. The email contains the company logo and looks professional. What is the most likely social engineering attack?
⚠ Common exam trap
The trap is that candidates may confuse phishing with whaling because both use email, but the key differentiator is the target: phishing is broad and untargeted, while whaling specifically targets high-level executives or individuals with privileged access. For example, an email targeting a CEO about a wire transfer is whaling, while an email targeting many employees about updating HR info is phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
Phishing is the correct answer because the attack uses a deceptive email that impersonates a legitimate entity (HR department) to trick the recipient into clicking a malicious link. This is a classic example of a broad, untargeted social engineering attack delivered via email, which is the defining characteristic of phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Whaling
Why it's wrong here
The email targets a new employee, not an executive, so it fails the whaling criterion of singling out senior figures such as the CEO or CFO for high-value fraud. Whaling is tempting because it also impersonates authority and uses a plausible pretext, but it would be correct only if the recipient held an executive role.
- ✓
Phishing
Why this is correct
Phishing uses a spoofed, professional-looking email impersonating a trusted internal sender such as HR to trick the recipient into clicking a link and surrendering credentials or financial details. The direct deposit lure and forged branding match this attack precisely.
- ✗
Vishing
Why it's wrong here
Vishing uses voice communication such as phone calls or voicemail to manipulate victims, so it cannot describe an email-based lure. It is tempting because vishing is a genuine social engineering technique, and would be the correct answer if the employee had instead received a phone call from someone impersonating HR requesting payroll details.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing requires an attacker to observe credentials or data directly over the victim's shoulder, which no email link can accomplish. It is tempting because it is a genuine social engineering technique, and would be correct if the scenario described someone watching a colleague type payroll details in a public space.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.