220-1102 Security Practice Question
A user receives a phone call from someone claiming to be from the company's IT help desk. The caller says they are performing a security audit and need the user's login credentials to verify their account access. Which type of social engineering attack is this?
⚠ Common exam trap
A common mix-up: candidates confuse vishing with pretexting because both involve a fabricated story, but the exam specifically tests the delivery vector—voice (vishing) versus the scenario itself (pretexting)—so the phone call makes vishing the correct answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
The attack described uses voice communication (a phone call) to trick the user into revealing sensitive information, which is the defining characteristic of vishing (voice phishing). Unlike phishing, which uses email or malicious links, vishing exploits social engineering over the phone to bypass technical controls like email filters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing typically refers to mass-scale attacks that use fraudulent emails, malicious links, or spoofed websites to harvest credentials and data. A direct telephone call is a voice channel, not a digital message, so the term falls short. Although both attack types are social engineering, the phone-based medium categorizes this incident as vishing, a voice-specific phishing variant.
- ✓
Vishing
Why this is correct
Vishing, or voice phishing, uses telephone calls to impersonate a trusted authority and manipulate the victim into revealing confidential information such as account numbers, passwords, or personal identifiers. In this scenario, the attacker's phone call pretending to be from '5' fits the definition exactly. The caller may also spoof caller ID to enhance credibility, but the essential tactic is social engineering through real-time voice interaction.
- ✗
Smishing
Why it's wrong here
Smishing, a portmanteau of SMS and phishing, operates strictly through text messages or messaging apps, delivering a deceptive link or urgent request in written form. A phone conversation is synchronous and verbal, not an asynchronous text-based message, so smishing does not apply here. Recognizing the difference matters because the response channel and attack delivery method inform the appropriate security control.
- ✗
Pretexting
Why it's wrong here
Pretexting involves constructing a fabricated scenario or assumed identity to convince the target to disclose information or perform an action, and it can be executed through many media, including email, chat, or in person. While the caller is unquestionably using a pretext, the identifying characteristic of this attack is the voice-phishing delivery method. Therefore, vishing is the more precise and preferred term on the CompTIA A+ exam, even though pretexting is a related component.
Go deeper
Related to this question
Learn chapter
Account Lockout Policies
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.