Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives a text message on their company-issued smartphone. The message appears to be from the IT department and states that the user's email password will expire in 24 hours and they must click a link to renew it. The link leads to a website that looks identical to the company's login page. The user is suspicious and reports it. Which type of social engineering attack is this?

⚠ Common exam trap

Watch out — candidates often confuse smishing with phishing because both involve fraudulent links, but the specific delivery method (SMS vs. email) is the key differentiator in the CompTIA 220-1102 exam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Smishing

Smishing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) sent to a smartphone, not email or voice. The message impersonates the IT department and uses a malicious link to harvest credentials, which is the hallmark of smishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering technique that typically arrives via email, using deceptive links, malicious attachments, or fake login pages to steal credentials or deliver malware. Although the term is sometimes used as a broad umbrella, established security frameworks such as NIST and the APWG’s Anti-Phishing Working Group classify email as the defining vector for phishing. Because the user in this scenario received a text message, the attack is properly categorized as smishing, not phishing, so this option is incorrect.

  • ✗

    Vishing

    Why it's wrong here

    Vishing, short for voice phishing, relies on phone calls, VoIP systems, or even pre-recorded robocalls to directly manipulate a victim into revealing sensitive information. The attacker may spoof caller ID or impersonate a bank or IT help desk, but the crucial distinction is that vishing requires an audio channel. Since the user received only a text message rather than a call, this option does not match the described vector and is therefore incorrect.

  • ✓

    Smishing

    Why this is correct

    Smishing is a portmanteau of SMS and phishing, where an attacker sends a text message containing a malicious link, a spoofed sender identity, or a request for personal information, often exploiting urgency or fear. This attack arrives on the user's company-issued device as an SMS, which directly matches the scenario. Because the delivery vector is text messaging, smishing is the correct classification for this social engineering attempt.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is a highly targeted form of spear phishing that specifically attacks senior executives, such as CEOs, CFOs, or other C-level personnel, using personalized, high-stakes content to maximize the chance of success. The scenario describes a general user receiving a text message, with no indication that the target holds a high-level position or that the content is tailored to an executive. Thus, whaling is incorrect because it mischaracterizes both the victim profile and the attack's target selection.

Go deeper

Related to this question

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.