Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A technician receives a phone call from someone who claims to be from the company's IT security team. The caller states that there is an urgent audit and asks the technician to provide their domain password to verify their identity. The technician provides the password. Which type of social engineering attack is this?

⚠ Common exam trap

It's easy for candidates to confuse vishing with phishing because both involve credential theft, but the key differentiator is the communication medium—voice (phone call) versus electronic (email or text)—and the CompTIA exam specifically tests this distinction under social engineering attack types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

B is correct because vishing (voice phishing) is a social engineering attack conducted over voice communication, such as a phone call, where the attacker impersonates a legitimate entity to trick the victim into revealing sensitive information. In this scenario, the technician received a phone call from someone claiming to be from the IT security team and was asked to provide their domain password, which is a classic vishing technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad social engineering category where attackers masquerade as legitimate entities, typically via email or malicious websites, to steal credentials or install malware. While vishing is a voice-based subtype, the term 'phishing' alone implies an electronic message with links or attachments. Because the incident here occurs over a phone call, it is more precisely vishing, not generic phishing.

  • ✓

    Vishing

    Why this is correct

    Vishing, or voice phishing, directly matches this scenario because the attacker initiated a phone call to deceive the technician. Attackers often spoof caller ID to appear as a trusted organization, create a sense of urgency, and request sensitive data such as passwords or PINs. It is the correct answer as it is the only option where the delivery medium is the telephone itself.

  • ✗

    Smishing

    Why it's wrong here

    Smishing (SMS phishing) uses text messages to trick recipients into clicking malicious links or replying with personal information, often through shortened URLs. The attack is carried out in written form via short message service, not through a real-time voice conversation. A phone call eliminates smishing because there is no text message involved in this scenario.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is a physical security attack where an unauthorized person follows an authorized employee through a secured door, often piggybacking on their legitimate access badge. It relies on in-person proximity and social engineering during the doorway entry, completely unrelated to telephone communication. Since the technician's interaction is remote and over a phone call, tailgating cannot be the correct classification.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.