Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives a text message on their company-issued smartphone claiming they won a gift card and must click a link to claim it. The link leads to a fake login page that harvests credentials. Which type of social engineering attack is this?

⚠ Common exam trap

Watch out — candidates often confuse smishing with phishing because both involve fake login pages, but the key differentiator is the delivery method—SMS versus email—and the exam expects you to identify the specific attack vector mentioned in the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smishing

B is correct because smishing is a social engineering attack that uses SMS (Short Message Service) text messages to trick recipients into clicking malicious links or providing sensitive information. In this scenario, the attack vector is a text message on a smartphone, which matches the definition of smishing (SMS + phishing). The fake login page harvesting credentials confirms the phishing component delivered via SMS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vishing

    Why it's wrong here

    Vishing (voice phishing) relies on phone calls, often using VoIP to spoof caller IDs and create a sense of urgency. The scenario describes a text message, not a live or pre-recorded call, so voice-based social engineering does not match the delivery method described. Even if the text contains a phone number, the initial attack vector is SMS, making smishing the more accurate term.

  • ✓

    Smishing

    Why this is correct

    Smishing is a portmanteau of SMS and phishing, where attackers send fraudulent text messages containing malicious links or requests for sensitive information. Because the user received a text message, this attack falls squarely under smishing, regardless of whether the payload is a link, attachment, or solicitation for a call-back. The gift-card lure is a common smishing technique designed to prompt immediate action.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is the broader category of social engineering that typically occurs via email, using deceptive messages to trick recipients into disclosing credentials or downloading malware. While smishing is a subset of phishing, the question describes a text message, so the more precise term is smishing rather than the umbrella term. Using 'phishing' alone would fail to indicate the SMS-based vector, which is critical for containment and user-awareness training.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing is a targeted form of attack that uses personally identifiable information (such as the victim's name, job title, or role) to increase credibility, often aimed at specific executives or systems. The given message—'you won a gift card'—is generic and lacks any personalized context, so it cannot be classified as spear phishing. Instead, it is a broad, scatter-shot attempt typical of smishing campaigns.

Go deeper

Related to this question

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.