Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives a phone call from someone claiming to be from the company's IT support desk. The caller states there is a critical security issue with the user's account and requests the user's login credentials and a verification code sent to their phone. The user provides the information. Which type of social engineering attack has occurred?

⚠ Common exam trap

Many candidates confuse the broader concept of pretexting with the specific attack vector; while the caller is pretexting (creating a false scenario), the exam expects you to identify the delivery method (phone call) as vishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

Vishing (voice phishing) is the correct classification because the attack was carried out via a phone call, where the attacker impersonated IT support to socially engineer the victim into revealing sensitive information. The use of a voice channel to request credentials and a verification code is the defining characteristic of vishing, as opposed to text-based or in-person methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is a broad social engineering technique in which an attacker fabricates a believable scenario or identity to manipulate a target into disclosing information or performing actions. However, it is a category of deception rather than a specific delivery method; the same fabricated excuse could be used via email, phone, or in person. In this scenario, the attack is conducted over a phone call, which specifically qualifies as vishing, making vishing the more precise and correct classification.

  • ✓

    Vishing

    Why this is correct

    Vishing (voice phishing) is a social engineering attack executed via telephone call, where the attacker impersonates a trusted authority, such as a bank representative or IT support, to create urgency and trick the victim into revealing confidential information like passwords, PINs, or credit card numbers. This matches the scenario exactly: the victim receives an unsolicited phone call from a supposed legitimate caller. Vishing often uses VoIP and caller ID spoofing to appear legitimate, making it the appropriate and correct answer.

  • ✗

    Smishing

    Why it's wrong here

    Smishing, or SMS phishing, is a social engineering attack that uses short message service (SMS) text messages to deceive victims, typically by embedding malicious links or requesting sensitive information via text. The attack vector is specifically text-based messaging rather than a real-time phone conversation. Since the user in this scenario received a phone call, not an SMS message, smishing does not apply here.

  • ✗

    Tailgaiting

    Why it's wrong here

    Tailgaiting is a physical security risk where an unauthorized person gains entry to a restricted area by following an authorized individual through a secured door or checkpoint, relying on the authorized person's access. It requires physical proximity and access control bypass, and it has no direct correlation to a phone call or digital communication. As the incident described involves a telephonic request for information, tailgaiting is not a plausible answer.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.