Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives a phone call from an individual claiming to be a help desk technician. The caller says the user's computer is infected with a virus and asks the user to download remote access software so the caller can fix it. The user complies and grants access. Which type of social engineering attack is this?

⚠ Common exam trap

Many exam-takers confuse vishing with phishing because both involve social engineering, but the key differentiator is the communication channel—vishing uses voice (phone calls) while phishing uses electronic messages (email/text).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

This is vishing (voice phishing) because the attacker uses a phone call to impersonate a help desk technician and socially engineer the user into installing remote access software. Unlike phishing, which relies on email or text, vishing exploits voice communication to bypass technical defenses and gain direct system access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad social engineering technique that typically involves deceptive emails with malicious links or attachments to steal credentials or install malware. In this scenario, the attack is initiated by a live voice phone call, not by an electronic written message. Therefore, while the call could theoretically be an attempt at phishing, the more precise term for the voice-based vector is vishing, so phishing is not the best answer.

  • ✓

    Vishing

    Why this is correct

    Vishing, or voice phishing, is the correct classification because the attacker uses a telephone call to impersonate a trusted entity and manipulate the user into revealing private information such as passwords, credit card numbers, or remote access. The attacker may spoof the caller ID to appear legitimate, but the defining characteristic is that the social engineering occurs over live or recorded voice communication. This directly matches the scenario where the user receives a phone call from an individual.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is a form of phishing delivered via SMS or text messaging, where the victim receives a text containing a malicious link or a prompt to call a number. In this case, the user's initial contact is an unsolicited incoming phone call, not a text message. Smishing requires the recipient to read and interact with a written message, so it cannot be the correct label for an attack that begins with a voice call.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is a social engineering technique where the attacker fabricates a believable scenario or identity—such as a bank investigator or IT support technician—to earn the victim's trust and extract information. While vishing attacks often use a pretext, pretexting itself does not specify the communication channel; it could occur in person, by email, or over the phone. Because the question asks specifically for the threat type given that the attack starts with a phone call, vishing is the more concrete and accurate answer, making pretexting secondary rather than the correct option.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.