Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user finds a USB drive labeled 'Employee Bonus Info' in the parking lot and plugs it into their workstation to view the contents. The workstation is immediately infected with malware that encrypts files and displays a ransom note. Which type of social engineering attack was this?

⚠ Common exam trap

Test-takers frequently confuse baiting with phishing because both involve tricking the user, but baiting specifically uses a physical object (like a USB drive) or a digital lure (like a free download) rather than a deceptive electronic message.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Baiting

This is baiting because the attacker left a physical USB drive in a location where it would likely be found, labeled with an enticing filename ('Employee Bonus Info') to exploit human curiosity. When the user plugged it into their workstation, the malware executed automatically (often via autorun.inf or a malicious executable disguised as a document), leading to ransomware encryption. Baiting relies on offering something desirable to trick the victim into performing an action that compromises security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering technique that typically uses electronic communication—such as email, SMS, or fake websites—to deceive victims into revealing credentials, installing malicious links, or providing sensitive data. Unlike the USB drive scenario, phishing does not rely on a physical object left for discovery; it depends on the attacker actively sending a lure and the victim responding to that direct invitation. The threat actor remains remote and never places a device in the victim's environment to exploit curiosity. Thus, while both are deceptive, the vector and delivery method are fundamentally different from leaving a labeled USB drive.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating, also known as piggybacking, is a physical security attack where an unauthorized person follows an employee through a controlled entry point, such as a secured door or turnstile, without presenting valid credentials. This tactic exploits door-prop openings, social courtesy, or inattention to gain physical access to a restricted area or facility. It does not involve leaving a storage medium like a USB drive, nor does it rely on a victim's curiosity to trigger a malware infection. Since the attacker is present and relies on proximity, not on the victim finding and using a device, tailgating is the wrong classification for this scenario.

  • ✓

    Baiting

    Why this is correct

    Baiting is a social engineering attack that offers something desirable—such as a USB drive labeled 'Employee Bonus Info'—to trick the victim into taking a risky action. In this case, the attacker plants the USB drive in a location where an employee is likely to find it, prompting the victim to insert it into a company computer out of curiosity or greed. Once connected, the drive may contain malware (e.g., a trojan or worm) that executes via autorun, USB Rubber Ducky-style keystroke injection, or a deceptive file the user opens, thereby compromising the system. This technique specifically exploits human curiosity and the promise of a reward, making baiting the correct answer for a physical device drop.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is an attack in which the perpetrator creates a fabricated scenario or false identity—such as pretending to be an IT technician, auditor, or banking representative—to manipulate a victim into voluntarily disclosing sensitive information. The attacker typically engages in direct communication (e.g., phone call, email, or in-person impersonation) and actively builds a phony narrative to gain trust. Unlike baiting, pretexting does not rely on leaving a physical device or making the victim act on an alluring find; instead, the victim is talked into cooperating. Because the USB drive scenario involves no impersonation or invented story spoken to the victim, pretexting is an incorrect classification.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.