Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A user receives a text message on their company-issued smartphone that appears to be from the IT department. The message states that the user's email account will be suspended unless they click a link and enter their credentials to verify the account. The user clicks the link, enters their username and password, and later discovers that their account has been compromised. Which type of social engineering attack is this?

⚠ Common exam trap

It's easy for candidates to choose 'Phishing' as a catch-all term, failing to recognize that CompTIA distinguishes smishing as the specific variant when the attack vector is SMS/text messaging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smishing

This is smishing because the attack uses SMS (Short Message Service) text messages as the delivery vector to trick the user into revealing credentials. Smishing is a subset of phishing that specifically exploits the trust users place in text-based mobile communications, often leveraging urgency and impersonation of internal IT departments to bypass email-based security filters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Smishing

    Why this is correct

    Smishing is correct because the attack was delivered through an SMS text message, making it a text-based form of social engineering. The attacker exploits the personal and immediate nature of texting to trick the user into clicking a malicious link or revealing credentials. Unlike email, SMS messages are often trusted more readily and can appear to come from a known contact or official source, increasing the attack's effectiveness.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is wrong because it specifically refers to fraudulent communications sent via email, often with spoofed sender addresses and embedded links that lead to fake login pages. Although smishing is a subcategory of the broader phishing umbrella, the medium of delivery is the key differentiator: this attack used SMS, not email. Calling it phishing would fail to capture the distinct vector and the security controls needed to mitigate it.

  • ✗

    Vishing

    Why it's wrong here

    Vishing is wrong because it relies on voice communication, typically through phone calls or VoIP services, rather than text messages. In a vishing attack, the attacker may impersonate a bank official or IT support and attempt to extract sensitive information through conversation. Since the user received a text message, not a call, this attack is not vishing by definition.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is wrong because it is a highly targeted form of spear phishing aimed at senior executives, CFOs, or other high-value individuals within an organization. The goal is usually to trick them into authorizing large wire transfers or revealing confidential corporate data, often via carefully crafted emails. This scenario describes a general user receiving an SMS, so it lacks the executive-level targeting and email-based delivery characteristic of whaling.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.