Courseiva
Security →easyMultiple Choice

220-1102 Vishing (Voice Phishing) Practice Question

A user receives a phone call from someone claiming to be from the company's IT help desk. The caller states there is a security breach and asks the user to confirm their login password and read back a multi-factor authentication code from their phone. The user complies. Which type of social engineering attack has occurred?

⚠ Common exam trap

It's easy for candidates to confuse vishing with phishing because both involve impersonation and credential theft, but the specific delivery method (voice call vs. email/SMS) is the critical differentiator that CompTIA tests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

B is correct because vishing (voice phishing) is a social engineering attack conducted over the phone, where the attacker impersonates a legitimate entity (here, the IT help desk) to trick the user into revealing sensitive information such as passwords and multi-factor authentication codes. The key element is the voice channel, which distinguishes it from other phishing variants.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is delivered by email or fraudulent websites, not a live voice call; vishing covers telephone-based pretexting. It tempts because phishing is the umbrella term for credential theft via social engineering, but the channel here is voice, which is the defining axis separating the two.

  • ✓

    Vishing

    Why this is correct

    Vishing is voice-based phishing conducted over a phone call, where the attacker impersonates IT and manipulates the user into revealing credentials and an MFA code. The telephone channel and verbal pretext distinguish it from email phishing, smishing, or pretexting.

  • ✗

    Smishing

    Why it's wrong here

    Smishing arrives as SMS text messages containing malicious links or requests, not voice calls. It tempts because smishing also targets credentials and MFA codes, but the delivery channel is text messaging; a phone call is vishing, which is the actual attack described.

  • ✗

    Shoulder surfing

    Why it's wrong here

    Shoulder surfing requires direct visual observation of a screen or keypad, not verbal manipulation over a call. It tempts because both are social engineering and both can capture credentials or MFA codes, but the mechanism here is a spoken pretext, which is vishing.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.