Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: A user calls the help desk, frantic because their…

A user calls the help desk, frantic because their banking app shows an unauthorized transfer of $500. They say they received a call earlier from 'bank security' asking them to install a remote access tool to 'verify their account'. What type of social engineering attack did the user fall victim to?

⚠ Common exam trap

CompTIA A+ 220-1202 often tests the distinction between vishing and phishing by emphasizing the communication medium (voice call vs. email), so candidates mistakenly choose phishing when the attack vector is a phone call rather than a digital message.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vishing

The user received a phone call (voice channel) and was tricked into installing remote access software, which is the hallmark of vishing (voice phishing). Unlike phishing, which uses email or malicious links, vishing exploits telephone systems and social engineering to gain unauthorized access or sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing primarily refers to fraudulent attempts to obtain sensitive information, such as usernames, passwords, and credit card details, by disguising as a trustworthy entity in an electronic communication. These attacks predominantly leverage email, sending deceptive messages that often contain malicious links or attachments. While vishing is a subset, the term 'phishing' alone typically implies an email-based vector, which does not align with a direct phone call scenario.

  • Vishing

    Why this is correct

    Vishing, or voice phishing, is a social engineering tactic that utilizes telephone calls to trick individuals into divulging personal or financial information, installing malware, or performing other actions detrimental to their security. Attackers often impersonate legitimate organizations, such as banks, government agencies, or tech support, creating a sense of urgency or fear to manipulate the victim. This method directly matches the scenario where a user is frantic after a phone call-initiated attack.

  • Smishing

    Why it's wrong here

    Smishing specifically refers to phishing attacks conducted via SMS (Short Message Service) text messages. These messages often contain malicious links designed to install malware or direct users to fraudulent websites that harvest credentials. Unlike the described scenario, which involves a direct voice call, smishing relies entirely on text-based communication to initiate the social engineering attempt.

  • Shoulder surfing

    Why it's wrong here

    Shoulder surfing is a low-tech social engineering technique where an attacker directly observes a victim, typically from behind or nearby, to obtain sensitive information like PINs, passwords, or other confidential data displayed on a screen or entered on a keypad. This method requires physical proximity and visual access to the target's actions. It is fundamentally different from a remote attack initiated through a phone call, which does not involve direct observation.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.