Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives a phone call from an individual claiming to be a member of the company's IT support team. The caller states that the user's email account has been compromised and requests the user's password to 'verify the account.' Which type of social engineering attack does this describe?

⚠ Common exam trap

The 220-1102 exam often tests the distinction between the attack vector (phone, email, SMS) and the underlying social engineering technique (pretexting), so candidates may incorrectly choose 'pretexting' because the caller is using a false identity, but the question specifically asks for the type of attack based on the communication channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

This is vishing (voice phishing) because the attack is carried out via a phone call, where the attacker impersonates IT support to trick the user into revealing their password. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to bypass technical defenses and exploit human trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    While phishing is an umbrella term for social-engineering attacks that trick users into exposing credentials or data, it generally refers to email or web-based lures that deliver a malicious link or attachment. A phone call with a live fraudster does not involve a digital payload or a hyperlink; instead it relies on a voice conversation to extract information. In security terminology, voice-based phishing has its own specific name: vishing.

  • ✓

    Vishing

    Why this is correct

    Vishing, or voice phishing, is the correct classification because the attacker uses a telephone call to impersonate a trusted entity and socially engineer the victim into revealing sensitive data like passwords, credit-card numbers, or security codes. The scammers often spoof caller ID or use VoIP and automated IVR menus to make the interaction seem legitimate. Since the entire attack flows through the voice channel, this maps directly to the definition of vishing.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is phishing performed via SMS or text message, in which the victim receives a short link, a fake notification, or a phone number to call. The attack described here begins with an unsolicited phone call, not a text message, so there is no SMS payload or message-app component. Choosing smishing would incorrectly identify the delivery medium as text, when the actual medium is a live voice call.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting refers to the act of creating a fabricated scenario or false identity, such as pretending to be from a bank's fraud department, to gain the victim's trust before requesting information. It is a social-engineering technique that can be used in vishing, but it is not the name of the phone-based attack itself. In this scenario, the telephone delivery method defines the category, making vishing the precise answer rather than the broader pretexting concept.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.