220-1102 Security Practice Question
A user receives a text message on their company-issued smartphone claiming they won a gift card and must click a link to claim it. The link leads to a fake login page that harvests credentials. Which type of social engineering attack is this?
⚠ Common exam trap
Watch out — candidates often confuse smishing with phishing because both involve fake login pages, but the key differentiator is the delivery method—SMS versus email—and the exam expects you to identify the specific attack vector mentioned in the scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
B is correct because smishing is a social engineering attack that uses SMS (Short Message Service) text messages to trick recipients into clicking malicious links or providing sensitive information. In this scenario, the attack vector is a text message on a smartphone, which matches the definition of smishing (SMS + phishing). The fake login page harvesting credentials confirms the phishing component delivered via SMS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) relies on phone calls, often using VoIP to spoof caller IDs and create a sense of urgency. The scenario describes a text message, not a live or pre-recorded call, so voice-based social engineering does not match the delivery method described. Even if the text contains a phone number, the initial attack vector is SMS, making smishing the more accurate term.
- ✓
Smishing
Why this is correct
Smishing is a portmanteau of SMS and phishing, where attackers send fraudulent text messages containing malicious links or requests for sensitive information. Because the user received a text message, this attack falls squarely under smishing, regardless of whether the payload is a link, attachment, or solicitation for a call-back. The gift-card lure is a common smishing technique designed to prompt immediate action.
- ✗
Phishing
Why it's wrong here
Phishing is the broader category of social engineering that typically occurs via email, using deceptive messages to trick recipients into disclosing credentials or downloading malware. While smishing is a subset of phishing, the question describes a text message, so the more precise term is smishing rather than the umbrella term. Using 'phishing' alone would fail to indicate the SMS-based vector, which is critical for containment and user-awareness training.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted form of attack that uses personally identifiable information (such as the victim's name, job title, or role) to increase credibility, often aimed at specific executives or systems. The given message—'you won a gift card'—is generic and lacks any personalized context, so it cannot be classified as spear phishing. Instead, it is a broad, scatter-shot attempt typical of smishing campaigns.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Short Message Service
Short Message Service (SMS) is a text messaging service that allows short messages to be sent between mobile phones, pagers, and other devices using standardized communication protocols.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.