220-1102 Security Practice Question
A user receives a text message on their company-issued smartphone. The message appears to be from the IT department and states that the user's email account will be deactivated unless they click a link to verify their credentials. The user clicks the link and enters their username and password. Which type of social engineering attack is this?
⚠ Common exam trap
Test-takers frequently confuse the delivery method (SMS vs. email vs. voice) and incorrectly select spear phishing or vishing, failing to recognize that smishing is defined solely by the use of text messaging as the attack vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
This is a smishing attack because the threat is delivered via SMS (Short Message Service) text message, tricking the user into clicking a malicious link and entering credentials. Smishing specifically uses text messaging as the vector, distinguishing it from voice-based vishing or email-based phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is performed over telephone networks, commonly using VoIP and caller ID spoofing to impersonate legitimate entities. Since the attack described occurs via an SMS text message, it does not align with the voice-based delivery mechanism that defines vishing. This distinction is critical: vishing requires an audio conversation or voicemail, whereas the scenario explicitly involves a text message.
- ✓
Smishing
Why this is correct
Smishing, a portmanteau of SMS and phishing, uses text messages to deceive targets into clicking malicious links or disclosing credentials. The scenario describes a user receiving a text message on a company-issued phone, which is the hallmark of a smishing attempt. Attackers often employ urgency, impersonation, or rewards to prompt quick action, and because SMS is a trusted channel, victims are more likely to comply than with unsolicited email.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a highly targeted attack that uses research to personalize messages, typically delivered via email, to a specific individual or role, unlike mass-cast smishing. The description gives no indication of personalization or targeting, and the message is sent as a text, not a crafted email, so it fails to meet the defining criteria. Furthermore, spear phishing often leverages social engineering based on the victim's public information, which is absent in this generic text-message scenario.
- ✗
Whaling
Why it's wrong here
Whaling is a specialized form of phishing aimed at high-profile executives like chief executives or CFOs, with the goal of stealing sensitive corporate data or initiating fraudulent wire transfers. The user in this scenario is simply "a user" with no stated executive status, and the attack is not described as highly targeted or involving significant financial impact. Even if a text message could be used for whaling, the context does not support that classification here.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Short Message Service
Short Message Service (SMS) is a text messaging service that allows short messages to be sent between mobile phones, pagers, and other devices using standardized communication protocols.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.