220-1102 Security Practice Question
A user receives an email claiming there is a suspicious login attempt on their account. The email asks the user to click a link immediately to verify their identity. The link leads to a website that looks identical to the company's login page but has a slightly different URL. Which type of social engineering attack is this?
⚠ Common exam trap
The 220-1102 exam often tests the distinction between generic phishing and targeted variants like spear phishing, where the trap is that candidates mistake any personalized-looking email for spear phishing, even when the attack lacks specific targeting details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This is a classic phishing attack because the email is a mass, unsolicited message that uses a deceptive link to a fraudulent website mimicking the legitimate login page. Phishing relies on volume and generic social engineering to trick users into revealing credentials, without targeting a specific individual or high-level executive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing
Why this is correct
Phishing is a broad, untargeted attack in which threat actors send mass emails impersonating a trusted entity, using urgent or generic lures to persuade victims to click a malicious link, open a booby-trapped attachment, or enter credentials on a fake login page. The scenario describes an unsolicited email claiming suspicious activity, which is a classic phishing pretext sent to a wide audience rather than tailored to any individual, making this the correct classification.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted variant that customizes the message with the recipient's name, job title, employer, or recent activities gleaned from open-source intelligence or a prior breach. The scenario provides no such personalization; it relies on a generic suspicious-activity warning, so it lacks the individual tailoring and reconnaissance that would justify classifying it as spear phishing.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) is a social-engineering vector conducted over PSTN, VoIP, or voicemail, using caller-ID spoofing, robocalls, or voice messages to extract personally identifiable information or financial data. Because the attack in the scenario is delivered entirely through email, not through any form of voice communication, vishing does not apply to this incident.
- ✗
Whaling
Why it's wrong here
Whaling is a highly targeted phishing attack that specifically goes after senior executives, C-suite officers, or other high-value individuals, often impersonating legal, regulatory, or business partners and using authority or urgency to trigger large financial transfers or sensitive data disclosure. The email here is sent to a regular user with a generic suspicious-activity notification, and while phishing can reach executives, the scenario does not identify the recipient as a high-profile target, so whaling is not correct.
Go deeper
Related to this question
Learn chapter
MFA Types for Users
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.