Courseiva
Security →easyMultiple Choice

220-1102 Vishing uses phone calls to deceive victims. Practice Question

A user receives a phone call from someone claiming to be from the IT department. The caller asks the user to provide their login credentials so a security update can be applied immediately. The user complies. Which type of social engineering attack has occurred?

⚠ Common exam trap

It's easy for candidates to confuse the medium of the attack (voice call) with the broader category of phishing, but CompTIA specifically distinguishes vishing as a voice-based variant of phishing, not phishing itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

Vishing (voice phishing) is the correct answer because the attack was carried out over a phone call, where the attacker impersonated IT staff to socially engineer the user into revealing login credentials. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to exploit human trust and urgency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Vishing

    Why this is correct

    Vishing (voice phishing) is a social engineering attack conducted over a live telephone call, in which the attacker impersonates a trusted authority—such as a bank, IT helpdesk, or government agency—to create urgency and manipulate the victim into disclosing sensitive information like credentials, PINs, or one-time passcodes. The attack vector is specifically voice, distinguishing it from email-based phishing or SMS-based smishing. This scenario exactly matches vishing: a phone call from someone posing as a legitimate entity, seeking confidential data. Caller ID spoofing, often via VoIP or ANII, can make the call appear official, reinforcing the social engineering pretext.

  • ✗

    Phishing

    Why it's wrong here

    Phishing typically involves a fraudulent electronic message, such as an email or fake website, to harvest credentials. This scenario lacks any digital lure; the attack is conducted entirely through a live telephone call, which is the defining mechanism of vishing (voice phishing). Phishing would be correct if the user had clicked a malicious link in an email rather than verbally disclosing credentials over the phone.

  • ✗

    Smishing

    Why it's wrong here

    Smishing relies on SMS text messages as the attack vector, but the scenario describes a phone call, not a text message. The correct classification is vishing (voice phishing), which uses a telephone call to extract credentials. Smishing would be the correct choice if the user had received a fraudulent text message containing a link or request for login details, as that is the precise delivery mechanism smishing targets.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is a physical security attack where an unauthorized individual follows an authorized person through a controlled access point—such as a badge-secured door, mantrap, or turnstile—by exploiting the authorized person's entry without presenting their own credentials. This technique requires direct, in-person proximity to a restricted facility and relies on social engineering or politeness to gain entry. In the given scenario, the victim is targeted remotely via a phone call, with no physical proximity or entry control involved. Therefore, tailgating is categorically incorrect because it is a physical access attack, not a telephony-based social engineering threat.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.