easyMultiple ChoiceObjective-mapped
220-1102 Practice Question: A user calls the help desk, frantic because they…
A user calls the help desk, frantic because they received an email from what appears to be the CEO asking them to urgently purchase $500 in gift cards for a client and reply with the codes. The email address looks slightly off, and the signature is missing the usual legal disclaimer. What type of social engineering attack is this most likely an example of?
⚠ Common exam trap
The CompTIA A+ exam often tests the distinction between phishing and pretexting by presenting a scenario where the attacker uses a fabricated story (pretext) but delivers it via email, leading candidates to choose pretexting instead of recognizing that the email delivery method makes it phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This is a classic example of phishing, specifically a subtype known as spear phishing or whaling, because the attacker impersonates a high-level executive (the CEO) to trick the user into performing a financial action. The telltale signs are the slightly off email address (spoofed domain or lookalike character) and the missing legal disclaimer, which are common indicators of a fraudulent email designed to harvest credentials or money. Phishing relies on social engineering to bypass technical controls by exploiting human trust and urgency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is a physical social engineering technique where an attacker directly observes a victim's screen or keystrokes to steal sensitive information, such as passwords, PINs, or confidential data. This method relies on proximity and visual access, often occurring in public or semi-private spaces. It does not involve digital communication or deceptive emails, making it irrelevant to a scenario describing an email-based attack.
- ✓
Phishing
Why this is correct
Phishing is a highly prevalent social engineering attack where cybercriminals send fraudulent communications, typically emails, designed to appear as if they originate from a legitimate and trustworthy source. The primary objective is to deceive recipients into revealing sensitive information, such as login credentials or financial details, or to perform harmful actions like purchasing gift cards. The scenario involving deceptive emails prompting gift card purchases perfectly aligns with the definition and common tactics of a phishing attack.
- ✗
Tailgating
Why it's wrong here
Tailgating, also known as piggybacking, is a physical security breach where an unauthorized individual gains access to a restricted area by closely following an authorized person. This typically occurs when an authorized person holds a door open or fails to ensure a secure entry point closes properly behind them. It is a physical social engineering tactic focused on bypassing access controls, not a digital attack vector involving deceptive emails.
- ✗
Pretexting
Why it's wrong here
Pretexting is a social engineering technique where an attacker creates a fabricated scenario or 'pretext' to manipulate a victim into divulging specific information or performing a particular action. While it involves deception, pretexting often relies on direct, often verbal, interaction (e.g., phone calls) where the attacker actively engages the victim in a believable, yet false, narrative. The primary attack vector described in the scenario, deceptive emails, makes phishing a more precise classification than pretexting.
Go deeper
Related to this question
Learn chapter
Virtualization and Client-Side
Key term
Spear phishing
Spear phishing is a targeted cyberattack in which a criminal sends a fraudulent email that appears to come from a trusted source, aiming to trick a specific person or organization into revealing sensitive data or installing malware.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.