Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives a phone call from someone claiming to be from the IT security team. The caller states that the user's account has been compromised and asks the user to verify their password to confirm identity. The user provides the password. Which type of social engineering attack is this?

⚠ Common exam trap

Candidates often confuse pretexting with phishing because both involve deception, but phishing specifically uses electronic communication channels (email, SMS, fake websites) rather than direct voice interaction or a fabricated backstory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pretexting

This is a pretexting attack because the caller fabricates a scenario (claiming to be from IT security) to trick the user into revealing sensitive information. Pretexting relies on a false identity and a fabricated story to gain trust, unlike phishing which typically uses electronic communication like email or fake websites. The direct request for the password over the phone is a hallmark of pretexting, not a technical exploit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering method that typically relies on electronic communication channels such as email, SMS, or fraudulent websites to trick victims into clicking malicious links, downloading malware, or entering credentials. It is not commonly conducted through a direct voice call; when a phone call is used to extract information or payment, that specific variant is known as vishing. In this scenario, the attacker's fabricated identity and narrative make pretexting the more precise classification.

  • ✓

    Pretexting

    Why this is correct

    Pretexting is a social engineering attack in which the perpetrator invents a plausible scenario—or pretext—to establish a false sense of legitimacy and trust with the target. The attacker may claim to be from a support desk, a bank, or a vendor and then use that fabricated authority to persuade the victim into revealing confidential information such as passwords, account numbers, or personal data. Because the caller has crafted a deceptive story to gain the user's cooperation, this matches the definition of pretexting exactly.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating, also known as piggybacking, is a physical security attack where an unauthorized person slips through a controlled access point by following an authorized individual, often without presenting credentials. This technique requires the attacker to be physically present at a door, turnstile, or gate—it cannot occur over a telephone call. Since the user only has voice contact with the caller, tailgating is not a plausible explanation for this incident.

  • ✗

    Shoulder surfing

    Why it's wrong here

    Shoulder surfing is an observational attack where the perpetrator directly looks over a victim's shoulder, uses a hidden camera, or otherwise visually captures sensitive information such as PINs, passwords, or screen content. It requires close physical proximity to the victim's device or documents. A phone call cannot provide the attacker with visual access to the user's screen or keyboard, so shoulder surfing is not applicable to this scenario.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.