Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports receiving a phone call from someone claiming to be from the company's help desk. The caller stated that there was a critical security issue and asked the user to provide their domain password to perform an emergency reset. The user complied. Which type of social engineering attack is this?

⚠ Common exam trap

It's easy for candidates to confuse vishing with phishing because both involve impersonation and credential harvesting, but the key differentiator is the communication medium—voice (phone) versus email.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

This is a vishing (voice phishing) attack because the social engineering was conducted over a phone call, where the attacker impersonated a help desk technician to trick the user into revealing their domain password. Unlike phishing (email) or SMiShing (SMS), vishing specifically uses voice communication to exploit human trust and urgency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is an email-based lure, whereas this attack used a voice call, making it vishing. It is tempting because phishing is the umbrella term for credential theft via impersonation, and it would be correct if the help-desk pretext had arrived as a message rather than a phone conversation.

  • ✓

    Vishing

    Why this is correct

    Vishing is voice-based phishing conducted over a telephone call, where the attacker impersonates a trusted party to extract credentials. The fake help-desk caller requesting the domain password for an alleged emergency reset matches this definition precisely, distinguishing it from email-based phishing.

  • ✗

    SMiShing

    Why it's wrong here

    SMiShing arrives via SMS text message, yet this credential request came through a voice call. It is tempting because SMiShing also impersonates a trusted party to harvest credentials, and it would be correct if the user had received a deceptive text rather than answering a phone call.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is physical entry following an authorised person through a secure door; no physical access occurred here. It is tempting because both exploit human trust, but tailgating would be correct only if the attacker had gained unauthorised entry to a restricted building or room.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.