220-1102 Security Practice Question
A user receives a text message on their company-issued smartphone that appears to be from the IT department. The message states that the user's email account will be suspended unless they click a link and enter their credentials to verify the account. The user clicks the link, enters their username and password, and later discovers that their account has been compromised. Which type of social engineering attack is this?
⚠ Common exam trap
It's easy for candidates to choose 'Phishing' as a catch-all term, failing to recognize that CompTIA distinguishes smishing as the specific variant when the attack vector is SMS/text messaging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
This is smishing because the attack uses SMS (Short Message Service) text messages as the delivery vector to trick the user into revealing credentials. Smishing is a subset of phishing that specifically exploits the trust users place in text-based mobile communications, often leveraging urgency and impersonation of internal IT departments to bypass email-based security filters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Smishing
Why this is correct
Smishing is correct because the attack was delivered through an SMS text message, making it a text-based form of social engineering. The attacker exploits the personal and immediate nature of texting to trick the user into clicking a malicious link or revealing credentials. Unlike email, SMS messages are often trusted more readily and can appear to come from a known contact or official source, increasing the attack's effectiveness.
- ✗
Phishing
Why it's wrong here
Phishing is wrong because it specifically refers to fraudulent communications sent via email, often with spoofed sender addresses and embedded links that lead to fake login pages. Although smishing is a subcategory of the broader phishing umbrella, the medium of delivery is the key differentiator: this attack used SMS, not email. Calling it phishing would fail to capture the distinct vector and the security controls needed to mitigate it.
- ✗
Vishing
Why it's wrong here
Vishing is wrong because it relies on voice communication, typically through phone calls or VoIP services, rather than text messages. In a vishing attack, the attacker may impersonate a bank official or IT support and attempt to extract sensitive information through conversation. Since the user received a text message, not a call, this attack is not vishing by definition.
- ✗
Whaling
Why it's wrong here
Whaling is wrong because it is a highly targeted form of spear phishing aimed at senior executives, CFOs, or other high-value individuals within an organization. The goal is usually to trick them into authorizing large wire transfers or revealing confidential corporate data, often via carefully crafted emails. This scenario describes a general user receiving an SMS, so it lacks the executive-level targeting and email-based delivery characteristic of whaling.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Impersonation
Impersonation is a security attack where an attacker pretends to be a legitimate person or system to gain unauthorized access, steal data, or commit fraud.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.