easyMultiple ChoiceObjective-mapped
220-1102 Practice Question: A user calls the help desk, frantic because their…
A user calls the help desk, frantic because their banking app shows an unauthorized transfer of $500. They say they received a call earlier from 'bank security' asking them to install a remote access tool to 'verify their account'. What type of social engineering attack did the user fall victim to?
⚠ Common exam trap
CompTIA A+ 220-1202 often tests the distinction between vishing and phishing by emphasizing the communication medium (voice call vs. email), so candidates mistakenly choose phishing when the attack vector is a phone call rather than a digital message.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
The user received a phone call (voice channel) and was tricked into installing remote access software, which is the hallmark of vishing (voice phishing). Unlike phishing, which uses email or malicious links, vishing exploits telephone systems and social engineering to gain unauthorized access or sensitive information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing primarily refers to fraudulent attempts to obtain sensitive information, such as usernames, passwords, and credit card details, by disguising as a trustworthy entity in an electronic communication. These attacks predominantly leverage email, sending deceptive messages that often contain malicious links or attachments. While vishing is a subset, the term 'phishing' alone typically implies an email-based vector, which does not align with a direct phone call scenario.
- ✓
Vishing
Why this is correct
Vishing, or voice phishing, is a social engineering tactic that utilizes telephone calls to trick individuals into divulging personal or financial information, installing malware, or performing other actions detrimental to their security. Attackers often impersonate legitimate organizations, such as banks, government agencies, or tech support, creating a sense of urgency or fear to manipulate the victim. This method directly matches the scenario where a user is frantic after a phone call-initiated attack.
- ✗
Smishing
Why it's wrong here
Smishing specifically refers to phishing attacks conducted via SMS (Short Message Service) text messages. These messages often contain malicious links designed to install malware or direct users to fraudulent websites that harvest credentials. Unlike the described scenario, which involves a direct voice call, smishing relies entirely on text-based communication to initiate the social engineering attempt.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is a low-tech social engineering technique where an attacker directly observes a victim, typically from behind or nearby, to obtain sensitive information like PINs, passwords, or other confidential data displayed on a screen or entered on a keypad. This method requires physical proximity and visual access to the target's actions. It is fundamentally different from a remote attack initiated through a phone call, which does not involve direct observation.
Go deeper
Related to this question
Learn chapter
File Systems: NTFS, FAT32, exFAT
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.