220-1102 Security Practice Question
A user receives a text message on their company-issued smartphone that appears to be from the CEO, asking the user to purchase gift cards and reply with the codes. The user notices the number is not the CEO's known number and reports it. Which type of social engineering attack is this?
⚠ Common exam trap
Watch out — candidates often confuse the medium (SMS) with the target (CEO), leading candidates to pick whaling because the CEO is impersonated, but the attack type is defined by the delivery channel, not the impersonated role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
Smishing (SMS phishing) is the correct answer because the attack uses a text message (SMS) to trick the user into purchasing gift cards and sharing the codes. The key indicator is the delivery method: a text message on a smartphone, not email or voice call, which directly matches the definition of smishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
While phishing is the broader category of credential-harvesting social engineering, the term is most precisely applied to email-based attacks. Security professionals classify SMS-delivered phishing separately as smishing, because text messages have unique trust signals, URL-obfuscation problems, and mobile-device risks. Labeling this as generic phishing hides the delivery channel and is therefore not the best answer.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) relies on real-time telephone calls, often routed over VoIP, where the attacker tries to persuade the victim to disclose passwords or payment details by speaking to them. The attack in the scenario is asynchronous and arrives as a text message, requiring the user to read and respond rather than converse. Because the entire attack surface is SMS rather than voice, vishing does not apply.
- ✓
Smishing
Why this is correct
Smishing is the exact security term for phishing attacks delivered via SMS/text messages. Attackers send a message impersonating a bank or service, often with an urgent alert and a shortened or spoofed URL, pressuring the user to tap a link or reply with account information. Because the user's company-issued phone received a fraudulent text, all elements of smishing are present.
- ✗
Whaling
Why it's wrong here
Whaling is a targeted spear-phishing variant aimed at senior executives, usually with personalized email lures involving business processes, legal threats, or big financial transactions. Nothing in the scenario indicates the recipient is an executive, and the delivery method is a text message, not the carefully crafted email whaling typically uses. This attack's target and medium do not match whaling.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.