220-1102 Security Practice Question
A user receives a phone call from an individual claiming to be from the company's IT security team. The caller states there is a breach and asks the user to verify their account by providing their username and password. Which social engineering technique is being used?
⚠ Common exam trap
Candidates often confuse the delivery method (phone call) with the general term 'phishing,' but CompTIA distinguishes vishing as a separate social engineering variant specifically for voice-based attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
Vishing (voice phishing) is the correct answer because the attack is conducted over a phone call, where the attacker impersonates IT security to trick the user into revealing credentials. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to exploit trust and urgency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a broad social engineering category that typically uses email or deceptive webpages to lure victims into entering credentials on fraudulent sites. The scenario describes a live phone call, which does not match the email-centric delivery method of classic phishing. While vishing is a voice-based variant of phishing, the specific term for a phone-call attack is not simply 'phishing'—it is vishing, making this option incorrect.
- ✓
Vishing
Why this is correct
Vishing, or voice phishing, is the correct classification because the attack is carried out over a phone call. The attacker impersonates a trusted individual to manipulate the user into revealing a username and password, exploiting the immediacy of voice communication and the difficulty of verifying the caller's identity. Unlike email-based phishing or SMS-based smishing, vishing relies on real-time social engineering delivered through telephony, which is exactly what the scenario describes.
- ✗
Smishing
Why it's wrong here
Smishing refers to phishing attacks that use SMS (Short Message Service) text messages as the attack vector. In a smishing attack, the victim receives a text containing a malicious link or a prompt to reply with personal data, not a real-time voice call. The scenario specifically involves a phone call, so the delivery mechanism does not align with smishing; it aligns with vishing, making smishing an incorrect option.
- ✗
Tailgating
Why it's wrong here
Tailgating relies on physical access, such as following an authorised person through a secured door without credentials, whereas the scenario describes a phone-based request for username and password. It is tempting because tailgating is a common social engineering attack that bypasses authentication controls, but it would only be correct if the attacker exploited physical proximity to enter a restricted area.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.