220-1102 Security Practice Question
A user receives a text message claiming to be from their bank, asking them to click a link to verify their account due to suspicious activity. Which type of social engineering attack is this?
⚠ Common exam trap
Many candidates confuse smishing with phishing because both involve fraudulent links, but the exam specifically tests the delivery method—SMS vs. email—as the distinguishing factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
Smishing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) rather than email or voice. The attacker uses social engineering via SMS to trick the user into clicking a malicious link, which is the defining characteristic of smishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
While phishing is a broad social engineering technique that uses fraudulent emails to trick recipients into revealing sensitive information, the scenario specifically identifies a text message as the delivery medium. Classic phishing relies on email as the attack vector, making it an incorrect choice here. Smishing is the specialized term for phishing conducted via SMS, which is why this answer does not match the described method.
- ✓
Smishing
Why this is correct
Smishing, short for SMS phishing, is a social engineering attack conducted through text messages in which the attacker poses as a legitimate organization (such as a bank) to deceive the recipient. The scenario describes a user receiving a text message claiming to be from their bank, which aligns exactly with this definition. This is the correct answer because the delivery mechanism is explicitly SMS, and smishing is the precise terminology for this form of phishing.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a phishing variant that relies on telephone calls or voicemail to manipulate victims into disclosing credentials, bank details, or other confidential information. Because the scenario states the user receives a text message rather than a phone call, vishing does not fit the attack description. The distinguishing factor between smishing and vishing is the communication channel, and here the channel is text-based, making vishing an incorrect option.
- ✗
Pretexting
Why it's wrong here
Pretexting is a broader social engineering tactic where an attacker invents a fabricated scenario or false identity to gain a victim's trust and extract information, often carried out via phone, email, or even in-person interactions. Although the fake bank message could be considered a form of pretext, the question focuses on the specific method described (SMS). Since pretexting is not defined by a particular communication channel and lacks the SMS vector, smishing is the more specific and accurate label for this attack.
Go deeper
Related to this question
Learn chapter
Account Lockout Policies
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.