Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives a phone call from someone claiming to be from the company's help desk, stating that their account has been compromised and they need to reset their password immediately. The caller asks for the user's current password to verify their identity. Which type of social engineering attack is this?

⚠ Common exam trap

The 220-1102 exam often tests the distinction between vishing and pretexting, where the trap is that candidates confuse the broad pretext (fabricated scenario) with the specific delivery method (phone call), but the question explicitly asks for the type of social engineering attack based on the communication channel used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

This is a vishing (voice phishing) attack because the attacker uses a phone call to impersonate the help desk and manipulate the user into revealing their current password. Vishing specifically exploits voice communication channels to bypass email-based security filters and directly target the victim's trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering technique that typically uses email or web-based messages with malicious links or attachments to harvest credentials. Here the caller is attempting to extract the user's password directly over a live phone call, not via a crafted electronic message. In A+ terminology, voice-based social engineering is classified as vishing, not phishing.

  • ✓

    Vishing

    Why this is correct

    Vishing is a voice-based form of phishing conducted over telephone calls, often using VoIP to spoof caller ID and appear as an internal help desk number. The attacker creates urgency or authority to pressure the user into revealing a password, which is a direct credential disclosure rather than a malware-delivery attempt. This scenario is vishing because the attack happens through a phone call.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is the SMS/text-message equivalent of phishing, where an attacker sends a text containing a link, callback number, or reply prompt to trick the victim into divulging credentials or installing malware. A live phone call from an impersonated help desk is not an SMS message, so even though the goal is social engineering, smishing does not match this attack vector.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting involves inventing a fabricated scenario, such as pretending to be a technician or vendor, to convince a victim to provide information, and it can occur in person, via email, or over the phone. However, because the communication medium here is a phone call and the attacker specifically asks for a password, the more precise CompTIA A+ classification is vishing. The help-desk story is the 'pretext' used inside the vishing attack, but it is not the overarching attack type.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.