220-1102 Pretexting Practice Question
A user receives a phone call from someone claiming to be from the IT help desk. The caller states that they are conducting a security audit and need the user's domain password to verify the account. The caller sounds professional and uses the user's name and department. The user provides the password. Later, the user's account is used to access sensitive data. Which type of social engineering attack occurred?
⚠ Common exam trap
Many candidates confuse vishing with pretexting because both involve phone calls, but vishing relies on a technical lure (e.g., fake caller ID, automated prompts) while pretexting relies on a fabricated story or role to gain trust.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is correct because the attacker created a fabricated scenario (a security audit) to establish legitimacy and trick the user into voluntarily disclosing their domain password. This social engineering technique relies on a false pretext to manipulate the victim, which is distinct from other attack vectors that use technical lures or physical breaches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing typically involves fraudulent emails or websites to obtain sensitive information, not phone calls. This attack used a phone call.
- ✓
Pretexting
Why this is correct
Pretexting relies on a fabricated story or pretext to gain the victim's trust and extract information. The caller posed as IT help desk staff, which is a classic example.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) uses phone calls to trick victims into providing sensitive information, but it often involves automated messages or fear tactics. This attack used a human caller with a detailed pretext, fitting pretexting more precisely.
- ✗
Tailgating
Why it's wrong here
Tailgating involves an unauthorized person following an authorized person into a restricted area. It does not involve phone calls or direct request for passwords.
Go deeper
Related to this question
Learn chapter
Data Classification Levels
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.