220-1102 Vishing (Voice Phishing) Practice Question
A user receives a phone call from someone claiming to be from the company's IT help desk. The caller states there is a security breach and asks the user to confirm their login password and read back a multi-factor authentication code from their phone. The user complies. Which type of social engineering attack has occurred?
⚠ Common exam trap
It's easy for candidates to confuse vishing with phishing because both involve impersonation and credential theft, but the specific delivery method (voice call vs. email/SMS) is the critical differentiator that CompTIA tests.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
B is correct because vishing (voice phishing) is a social engineering attack conducted over the phone, where the attacker impersonates a legitimate entity (here, the IT help desk) to trick the user into revealing sensitive information such as passwords and multi-factor authentication codes. The key element is the voice channel, which distinguishes it from other phishing variants.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is delivered by email or fraudulent websites, not a live voice call; vishing covers telephone-based pretexting. It tempts because phishing is the umbrella term for credential theft via social engineering, but the channel here is voice, which is the defining axis separating the two.
- ✓
Vishing
Why this is correct
Vishing is voice-based phishing conducted over a phone call, where the attacker impersonates IT and manipulates the user into revealing credentials and an MFA code. The telephone channel and verbal pretext distinguish it from email phishing, smishing, or pretexting.
- ✗
Smishing
Why it's wrong here
Smishing arrives as SMS text messages containing malicious links or requests, not voice calls. It tempts because smishing also targets credentials and MFA codes, but the delivery channel is text messaging; a phone call is vishing, which is the actual attack described.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing requires direct visual observation of a screen or keypad, not verbal manipulation over a call. It tempts because both are social engineering and both can capture credentials or MFA codes, but the mechanism here is a spoken pretext, which is vishing.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.