220-1102 Vishing Practice Question
A user receives a phone call from someone claiming to be from the company's IT help desk. The caller states that the user's account has been compromised and they need the user to install a remote desktop application to perform emergency repairs. The user complies and grants the caller access. Which type of social engineering attack has occurred?
⚠ Common exam trap
Many exam-takers confuse vishing with phishing because both involve deception, but the key differentiator is the communication medium: vishing uses voice (phone calls), while phishing uses electronic messages (email, SMS).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
B is correct because vishing (voice phishing) is a social engineering attack conducted over the phone, where the attacker impersonates a legitimate entity (here, the IT help desk) to manipulate the victim into performing a security-compromising action. The user received a phone call, not an email or text, which is the defining vector of vishing. The attacker's goal was to gain remote access by having the user install a remote desktop application, which is a common vishing payload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pretexting
Why it's wrong here
Pretexting is a broad social engineering technique where an attacker fabricates a scenario, or pretext, to manipulate a victim into revealing information or performing an action. The caller certainly used a pretext by pretending to be IT support, but the specific and correct classification is vishing because the attack was executed via a phone call. Pretexting can also occur through email, chat, or in person, and it is not the most precise term for a voice-based social engineering attack.
- ✓
Vishing
Why this is correct
Vishing, also known as voice phishing, is an attack that uses telephone or VoIP technology to trick a victim into giving up sensitive data or installing malware. In this case, the attacker called the user, impersonated a technician, and instructed the installation of remote control software, which is a classic vishing scenario. The voice channel is the deciding factor; the attacker engaged in real-time conversation to build trust and direct actions, rather than sending an email or text. This aligns with CompTIA A+ objectives that categorize voice-based social engineering as vishing.
- ✗
Phishing
Why it's wrong here
Phishing occurs through fraudulent emails, text messages, or fake websites designed to deceive users into disclosing credentials or downloading malware. The attack here began with a live telephone call, and the attacker gave spoken directions to install software, not a malicious link or attachment in a message. Although phishing and vishing share social engineering objectives, they are separated by their medium: phishing uses written communication, while vishing uses voice.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is the direct physical observation of a victim's screen, keyboard, or documents to capture passwords or other confidential information, typically in busy public places. In this incident, the attacker was not physically present and did not watch the user; the interaction was entirely carried out over the phone. Because the user was compromised by following verbal instructions rather than by being visually observed, shoulder surfing is not a valid classification here.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.