Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is helping a customer configure a…

A technician is helping a customer configure a new laptop. The customer mentions they received a pop-up on their old computer warning of a virus and a phone number to call for support. The customer called the number and gave remote access to a 'technician' who then installed several programs. What social engineering attack occurred?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Tech support scam

This is a classic tech support scam, a form of social engineering where attackers use fake virus warnings to gain remote access. The pop-up is designed to scare the user into calling a fraudulent support number. Once access is granted, the attacker can install malware or steal data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Shoulder surfing

    Why it's wrong here

    Shoulder surfing is a social engineering technique where an attacker directly observes a victim's screen or keyboard input to steal sensitive information like passwords or PINs. This method requires physical proximity to the target, allowing the attacker to visually "look over their shoulder." It does not involve remote access, pop-up alerts, or phone calls, making it irrelevant to a scenario describing a digital scam that prompts user interaction from a distance.

  • Phishing

    Why it's wrong here

    Phishing is a social engineering attack where an attacker attempts to trick individuals into revealing sensitive information, often through deceptive emails, text messages (smishing), or websites that mimic legitimate entities. While it aims to solicit information or actions, the primary vector is typically a fraudulent communication designed to appear authentic. A pop-up alert directly prompting a phone call, rather than directing to a fake website or requesting direct input, deviates from the typical phishing methodology.

  • Tech support scam

    Why this is correct

    A tech support scam is a form of social engineering where fraudsters impersonate legitimate technical support personnel or companies. They typically use unsolicited pop-up alerts, often displaying alarming security warnings or error messages, to panic users into calling a fake support number. Once contact is established, the scammers then manipulate the victim into granting remote access to their computer or paying for unnecessary "fixes," directly matching the described scenario of a pop-up prompting a phone call.

  • Dumpster diving

    Why it's wrong here

    Dumpster diving is a physical reconnaissance technique where attackers search through discarded materials, such as trash bins or recycling containers, to find sensitive information. This can include documents containing account numbers, passwords, personal details, or even hardware components. As it relies entirely on the physical retrieval of discarded items, it is completely unrelated to a digital scam involving pop-up alerts, phone calls, or remote access attempts.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.