Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: A user calls the help desk claiming they received…

A user calls the help desk claiming they received an urgent email from the CEO asking them to purchase gift cards for a client and reply with the codes. The user is suspicious because the email address looks slightly off. What type of social engineering attack is this?

⚠ Common exam trap

CompTIA A+ often tests the distinction between social engineering attack types by using a scenario that involves electronic communication (email) to trick the user, leading candidates to confuse phishing with physical or observation-based attacks like shoulder surfing or tailgating.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing

This is a phishing attack because the attacker impersonates a trusted entity (the CEO) via email to trick the user into performing a fraudulent action (purchasing gift cards and sharing codes). The suspicious email address indicates a spoofed sender, a common phishing technique that exploits trust and urgency to bypass user skepticism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Shoulder surfing

    Why it's wrong here

    Shoulder surfing is a social engineering technique where an attacker directly observes a victim's screen or keyboard input to steal sensitive information, such as passwords, PINs, or confidential data. This method relies on physical proximity and direct visual access, making it distinct from cyberattacks involving electronic communication like deceptive emails. It is a form of direct, low-tech espionage, not a remote digital attack.

  • Phishing

    Why this is correct

    Phishing is a cybercrime that employs fraudulent electronic communications, most commonly emails, to deceive individuals into divulging sensitive information like usernames, passwords, credit card details, or performing actions such as transferring funds or purchasing gift cards. Attackers impersonate legitimate entities to gain trust, making the deceptive email the primary vector for this social engineering attack. This directly aligns with a user receiving a deceptive email.

  • Tailgating

    Why it's wrong here

    Tailgating, also known as piggybacking, is a physical security breach where an unauthorized individual gains access to a restricted area by closely following an authorized person through a controlled entry point, such as a door requiring a badge or keycard. This method exploits human courtesy or inattention to bypass physical access controls and does not involve any form of electronic communication or deceptive emails.

  • Dumpster diving

    Why it's wrong here

    Dumpster diving is a reconnaissance technique where attackers search through discarded waste, such as trash bins or recycling containers, for sensitive information. This can include documents, old hard drives, or other media containing confidential data like account numbers, employee lists, or system configurations. This method is entirely physical and does not involve sending deceptive emails or any form of electronic communication.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.