Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives a phone call from an individual claiming to be from the company's IT security team. The caller states there is a breach and asks the user to verify their account by providing their username and password. Which social engineering technique is being used?

⚠ Common exam trap

Candidates often confuse the delivery method (phone call) with the general term 'phishing,' but CompTIA distinguishes vishing as a separate social engineering variant specifically for voice-based attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

Vishing (voice phishing) is the correct answer because the attack is conducted over a phone call, where the attacker impersonates IT security to trick the user into revealing credentials. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to exploit trust and urgency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad social engineering category that typically uses email or deceptive webpages to lure victims into entering credentials on fraudulent sites. The scenario describes a live phone call, which does not match the email-centric delivery method of classic phishing. While vishing is a voice-based variant of phishing, the specific term for a phone-call attack is not simply 'phishing'—it is vishing, making this option incorrect.

  • ✓

    Vishing

    Why this is correct

    Vishing, or voice phishing, is the correct classification because the attack is carried out over a phone call. The attacker impersonates a trusted individual to manipulate the user into revealing a username and password, exploiting the immediacy of voice communication and the difficulty of verifying the caller's identity. Unlike email-based phishing or SMS-based smishing, vishing relies on real-time social engineering delivered through telephony, which is exactly what the scenario describes.

  • ✗

    Smishing

    Why it's wrong here

    Smishing refers to phishing attacks that use SMS (Short Message Service) text messages as the attack vector. In a smishing attack, the victim receives a text containing a malicious link or a prompt to reply with personal data, not a real-time voice call. The scenario specifically involves a phone call, so the delivery mechanism does not align with smishing; it aligns with vishing, making smishing an incorrect option.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating relies on physical access, such as following an authorised person through a secured door without credentials, whereas the scenario describes a phone-based request for username and password. It is tempting because tailgating is a common social engineering attack that bypasses authentication controls, but it would only be correct if the attacker exploited physical proximity to enter a restricted area.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.