220-1102 Security Practice Question
A user receives an email from an unknown sender with an attachment labeled 'Invoice_2024.zip'. The user opens the attachment, which contains an executable file. The user runs the executable, and the workstation starts encrypting files. Which type of social engineering attack is this?
⚠ Common exam trap
Many exam-takers confuse the broad category of phishing with the more specific spear phishing, but the lack of any personalized details in the email (such as the user's name or company-specific information) clearly indicates a generic phishing attack, not a targeted one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This is a phishing attack because the user received an unsolicited email from an unknown sender containing a malicious attachment (Invoice_2024.zip) that, when opened and executed, triggered ransomware encryption. Phishing is a broad social engineering technique that uses deceptive emails to trick recipients into performing actions like opening attachments or clicking links, without requiring any personalization or targeting of a specific individual.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing
Why this is correct
Phishing is a broad, untargeted social-engineering attack in which an attacker sends the same generic e-mail to thousands of recipients, often impersonating a trusted brand or service to lure the victim into clicking a malicious link or opening an infected attachment. The message typically creates urgency—such as a compromised account or a failed delivery—to bypass rational decision-making. Because the email is not customized with the recipient's personal or professional details, this scenario fits generic phishing exactly.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted variant in which the attacker researches the victim beforehand and crafts a personalized e-mail using details such as the recipient's full name, job title, department, or recent activities, increasing the message's perceived legitimacy. The unknown-sender email described in the scenario contains no such personalization and appears sent broadly, so it cannot be classified as spear phishing even if a particular user happens to receive it.
- ✗
Whaling
Why it's wrong here
Whaling is spear phishing aimed specifically at high-profile executives like a CEO, CFO, or other senior leaders, often impersonating a vendor or legal authority to authorize wire transfers or disclose confidential corporate data. The scenario gives no indication that the recipient is an executive or that the attack is tailored to a high-value target; it describes an ordinary user receiving a generic email, which is the opposite of whaling.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is conducted over the telephone using VoIP systems or intentionally spoofed caller IDs to trick victims into providing account credentials, PINs, or security codes during a live voice call. Since the question explicitly states the attack vector is an email from an unknown sender, vishing is eliminated because it relies on a voice channel rather than an electronic message.
Go deeper
Related to this question
Learn chapter
Wireless Encryption: WEP, WPA, WPA2, WPA3
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.