Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives a text message on their company-issued smartphone that appears to be from the CEO, asking the user to purchase gift cards and reply with the codes. The user notices the number is not the CEO's known number and reports it. Which type of social engineering attack is this?

⚠ Common exam trap

Watch out — candidates often confuse the medium (SMS) with the target (CEO), leading candidates to pick whaling because the CEO is impersonated, but the attack type is defined by the delivery channel, not the impersonated role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smishing

Smishing (SMS phishing) is the correct answer because the attack uses a text message (SMS) to trick the user into purchasing gift cards and sharing the codes. The key indicator is the delivery method: a text message on a smartphone, not email or voice call, which directly matches the definition of smishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    While phishing is the broader category of credential-harvesting social engineering, the term is most precisely applied to email-based attacks. Security professionals classify SMS-delivered phishing separately as smishing, because text messages have unique trust signals, URL-obfuscation problems, and mobile-device risks. Labeling this as generic phishing hides the delivery channel and is therefore not the best answer.

  • ✗

    Vishing

    Why it's wrong here

    Vishing (voice phishing) relies on real-time telephone calls, often routed over VoIP, where the attacker tries to persuade the victim to disclose passwords or payment details by speaking to them. The attack in the scenario is asynchronous and arrives as a text message, requiring the user to read and respond rather than converse. Because the entire attack surface is SMS rather than voice, vishing does not apply.

  • ✓

    Smishing

    Why this is correct

    Smishing is the exact security term for phishing attacks delivered via SMS/text messages. Attackers send a message impersonating a bank or service, often with an urgent alert and a shortened or spoofed URL, pressuring the user to tap a link or reply with account information. Because the user's company-issued phone received a fraudulent text, all elements of smishing are present.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is a targeted spear-phishing variant aimed at senior executives, usually with personalized email lures involving business processes, legal threats, or big financial transactions. Nothing in the scenario indicates the recipient is an executive, and the delivery method is a text message, not the carefully crafted email whaling typically uses. This attack's target and medium do not match whaling.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.