Courseiva
Security →mediumMultiple Choice

220-1102 Practice Question: Vishing uses phone calls as the attack vector.

A user receives a phone call from an individual claiming to be from the company's IT help desk. The caller states that there is a critical security update and asks the user for their login credentials to apply the update. Which type of social engineering attack is this?

⚠ Common exam trap

CompTIA often tests the distinction between phishing, vishing, and smishing by focusing on the delivery vector—email, voice, or SMS—so candidates must remember that the medium of communication defines the attack type, not just the goal of credential theft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

This is a vishing (voice phishing) attack because the social engineering is conducted over a phone call, where the attacker impersonates IT help desk personnel to trick the user into revealing login credentials. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to bypass email filters and exploit human trust through direct verbal interaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is the broad, umbrella term for social-engineering attacks that use disguised electronic communications—most commonly email—to trick recipients into revealing credentials, clicking malicious links, or downloading malware. While vishing is a subset of phishing, the general term is imprecise here because the attack specifically occurred over voice telephony; the more accurate and specific answer is vishing, making phishing a less correct choice.

  • ✓

    Vishing

    Why this is correct

    Vishing (voice phishing) is a social-engineering attack conducted over phone calls, often using VoIP to spoof caller ID and impersonate legitimate organizations such as banks, government agencies, or technical support. The attacker creates a sense of urgency or authority to manipulate the victim into disclosing sensitive data like passwords, credit card numbers, or one-time codes, directly matching the scenario presented.

  • ✗

    Smishing

    Why it's wrong here

    Smishing (SMS phishing) is a social-engineering attack delivered via text message, typically containing a malicious link or a request to reply with personal or financial data. Because the initial vector is the Short Message Service rather than a live voice call, the scenario described—a phone call—does not match Smishing's defining channel, making it an incorrect answer.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating (or piggybacking) is a physical access-control attack in which an attacker follows an authorized person through a door or turnstile without presenting valid credentials, often by pretending to have forgotten a badge or carrying boxes. It exploits human courtesy and proximity rather than any telecommunications channel, so it is inapplicable to a phone call-based deception scenario.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.