220-1102 Security Practice Question
A user receives a phone call from someone claiming to be from the company's help desk, stating that their account has been compromised and they need to reset their password immediately. The caller asks for the user's current password to verify their identity. Which type of social engineering attack is this?
⚠ Common exam trap
The 220-1102 exam often tests the distinction between vishing and pretexting, where the trap is that candidates confuse the broad pretext (fabricated scenario) with the specific delivery method (phone call), but the question explicitly asks for the type of social engineering attack based on the communication channel used.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
This is a vishing (voice phishing) attack because the attacker uses a phone call to impersonate the help desk and manipulate the user into revealing their current password. Vishing specifically exploits voice communication channels to bypass email-based security filters and directly target the victim's trust.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering technique that typically uses email or web-based messages with malicious links or attachments to harvest credentials. Here the caller is attempting to extract the user's password directly over a live phone call, not via a crafted electronic message. In A+ terminology, voice-based social engineering is classified as vishing, not phishing.
- ✓
Vishing
Why this is correct
Vishing is a voice-based form of phishing conducted over telephone calls, often using VoIP to spoof caller ID and appear as an internal help desk number. The attacker creates urgency or authority to pressure the user into revealing a password, which is a direct credential disclosure rather than a malware-delivery attempt. This scenario is vishing because the attack happens through a phone call.
- ✗
Smishing
Why it's wrong here
Smishing is the SMS/text-message equivalent of phishing, where an attacker sends a text containing a link, callback number, or reply prompt to trick the victim into divulging credentials or installing malware. A live phone call from an impersonated help desk is not an SMS message, so even though the goal is social engineering, smishing does not match this attack vector.
- ✗
Pretexting
Why it's wrong here
Pretexting involves inventing a fabricated scenario, such as pretending to be a technician or vendor, to convince a victim to provide information, and it can occur in person, via email, or over the phone. However, because the communication medium here is a phone call and the attacker specifically asks for a password, the more precise CompTIA A+ classification is vishing. The help-desk story is the 'pretext' used inside the vishing attack, but it is not the overarching attack type.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.