220-1102 Security Practice Question
A user reports receiving a phone call from someone claiming to be from the company's help desk. The caller stated that there was a critical security issue and asked the user to provide their domain password to perform an emergency reset. The user complied. Which type of social engineering attack is this?
⚠ Common exam trap
It's easy for candidates to confuse vishing with phishing because both involve impersonation and credential harvesting, but the key differentiator is the communication medium—voice (phone) versus email.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
This is a vishing (voice phishing) attack because the social engineering was conducted over a phone call, where the attacker impersonated a help desk technician to trick the user into revealing their domain password. Unlike phishing (email) or SMiShing (SMS), vishing specifically uses voice communication to exploit human trust and urgency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is an email-based lure, whereas this attack used a voice call, making it vishing. It is tempting because phishing is the umbrella term for credential theft via impersonation, and it would be correct if the help-desk pretext had arrived as a message rather than a phone conversation.
- ✓
Vishing
Why this is correct
Vishing is voice-based phishing conducted over a telephone call, where the attacker impersonates a trusted party to extract credentials. The fake help-desk caller requesting the domain password for an alleged emergency reset matches this definition precisely, distinguishing it from email-based phishing.
- ✗
SMiShing
Why it's wrong here
SMiShing arrives via SMS text message, yet this credential request came through a voice call. It is tempting because SMiShing also impersonates a trusted party to harvest credentials, and it would be correct if the user had received a deceptive text rather than answering a phone call.
- ✗
Tailgating
Why it's wrong here
Tailgating is physical entry following an authorised person through a secure door; no physical access occurred here. It is tempting because both exploit human trust, but tailgating would be correct only if the attacker had gained unauthorised entry to a restricted building or room.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.