Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives a phone call from someone claiming to be from the company's help desk. The caller states that the user's computer has been sending suspicious network traffic and that the user must immediately install remote access software to allow the technician to fix it. The user complies. Which type of social engineering attack is this?

⚠ Common exam trap

Watch out — candidates often confuse vishing with phishing because both involve deception, but the specific attack vector (phone call vs. email/SMS) is the critical differentiator the exam tests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

B is correct because vishing (voice phishing) is a social engineering attack conducted over voice calls, where the attacker impersonates a legitimate entity (e.g., help desk) to trick the user into taking a harmful action, such as installing remote access software. The key indicator is the phone call itself, which distinguishes vishing from other phishing variants that rely on email or SMS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad social engineering category that usually involves fraudulent emails with malicious links or attachments designed to steal credentials or install malware. While vishing is technically a subset of phishing, the term 'phishing' alone is too generic and does not specify the voice-based delivery method used here. Because the attack vector in this scenario is a phone call, not an email message, the precise label is vishing, not phishing.

  • ✓

    Vishing

    Why this is correct

    Vishing, or voice phishing, is a social engineering attack conducted over phone calls where the attacker impersonates a trusted entity, such as a bank or technical support, to manipulate the victim into revealing sensitive information like passwords, credit card numbers, or security codes. The call often uses caller ID spoofing to appear legitimate, increasing the victim's trust. Since the user received a phone call, this attack is correctly identified as vishing, which is the voice-specific variant of phishing.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is a phishing attack carried out via SMS text messages, where the attacker sends a text containing a malicious link, a fake phone number, or a prompt to reply with personal details. Unlike vishing, smishing relies on written text messages rather than live or automated phone calls. Because the user received a phone call, not an SMS, this option does not match the described attack vector.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing is a highly targeted form of phishing that usually occurs via email, where the attacker customizes the message for a specific individual or organization using personal information to increase credibility. The attack here is a phone call, not an email, and there is no indication of prior research or personalization based on the user's identity. Even if the call were targeted, the voice-based delivery would still classify it as vishing, making spear phishing an incorrect answer.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.