220-1102 Security Practice Question
A user receives a phone call from someone claiming to be from the IT help desk. The caller asks for the user's domain password to perform a security audit. The user provides the password. Later, the user's account is used to access sensitive data. Which type of social engineering attack occurred?
⚠ Common exam trap
Candidates often confuse vishing with pretexting, but the exam expects you to recognize that the phone call medium specifically defines vishing, whereas pretexting is the overarching scenario that can be executed via any communication channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
B is correct because vishing (voice phishing) is a social engineering attack conducted over the phone, where the attacker impersonates a legitimate entity (here, the IT help desk) to trick the user into revealing sensitive information, such as a domain password. The user's subsequent account compromise confirms the attack succeeded via voice call, which is the defining characteristic of vishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a fraudulent email, message or website that harvests credentials electronically; this attack used a live voice call, which is vishing. Phishing is tempting because it is the most common credential-theft social engineering category, and it would be correct had the attacker sent a spoofed email or login page instead of telephoning.
- ✓
Vishing
Why this is correct
Vishing is voice-based phishing: the attacker used a phone call, impersonating IT help desk staff, to manipulate the user into disclosing the domain password. The subsequent account compromise confirms credential theft through telephone social engineering rather than email or SMS.
- ✗
Smishing
Why it's wrong here
Smishing is credential harvesting delivered by SMS text message, whereas this attack arrived as a telephone voice call, making it vishing. Smishing is tempting because it is another phone-based social engineering channel, and it would be the correct answer if the fake help-desk request had been sent as a text message.
- ✗
Pretexting
Why it's wrong here
Pretexting is the invented scenario or cover story used to justify a request, not the delivery channel; the question asks for the attack type, which is vishing because the pretext was delivered by voice call. Pretexting would be correct if the question asked what technique the caller employed.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.