Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A user reports receiving a phone call from someone claiming to be from the IT department. The caller asks the user to install a remote access tool to help fix a network issue. The user complies. Later, the technician discovers that the remote access tool was used to install malware. Which type of social engineering attack is this?

⚠ Common exam trap

Test-takers frequently confuse 'pretexting' with any impersonation attack, but the key differentiator is the communication channel—vishing specifically uses voice calls, while pretexting can occur via email or in person without a direct request for action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

Vishing (voice phishing) is a social engineering attack conducted over the phone. In this scenario, the attacker impersonated IT support to trick the user into installing a remote access tool, which was then used to deploy malware. The use of a phone call to elicit a security-compromising action is the hallmark of vishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Vishing

    Why this is correct

    Vishing is correct because it is a voice-based social engineering attack where an attacker impersonates IT support over the phone to coerce the victim into a harmful action—here, installing software. Unlike email phishing, vishing exploits the trust and authority of a live voice, often enhanced by caller ID spoofing to appear as an internal number. The requested installation likely delivers a remote-access trojan or backdoor, giving the attacker a foothold.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is incorrect because, while the attacker uses a fabricated IT identity (a pretext), the goal is not primarily to elicit sensitive information like credentials or personal data. In pure pretexting, the attacker typically fishes for data by engaging in a crafted dialogue. Here, the caller directly instructs the user to perform an action—install software—which is the hallmark of vishing, not a pretext-driven information disclosure.

  • ✗

    Baiting

    Why it's wrong here

    Baiting is incorrect because that technique relies on a tempting physical or digital lure, such as an infected USB drive left in a parking lot or a free download offered for the victim to discover. The attack in the question is initiated via an unsolicited phone call, with no physical artifact or curiosity-driven trap involved. Baiting requires the victim to voluntarily take the bait; here the attacker actively contacts the victim, which is characteristic of vishing.

  • ✗

    Quid pro quo

    Why it's wrong here

    Quid pro quo is incorrect because it involves offering a benefit or service in exchange for the victim's compliance, such as a fake security update in return for credentials or access. In these scenarios, the attacker makes an explicit reciprocal trade. The caller in this question simply asserts an IT role and demands software installation, offering no tangible benefit or quid pro quo; the malicious outcome comes directly from the installed software, not from a bargaining exchange.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.