220-1102 Security Practice Question
A user receives an email from their bank stating that there has been suspicious activity on their account and they must click a link to verify their identity. The email address looks slightly off, and the user is suspicious. Which type of social engineering attack is this?
⚠ Common exam trap
A common mix-up: candidates confuse phishing with vishing or smishing because all three involve impersonation, but the key differentiator is the communication medium—email for phishing, voice for vishing, and SMS for smishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This attack is phishing because it uses a deceptive email that appears to come from a legitimate source (the bank) to trick the user into clicking a malicious link. The slightly off email address is a classic indicator of phishing, where attackers spoof sender information to harvest credentials or install malware. Phishing specifically targets users via email, distinguishing it from other social engineering vectors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing
Why this is correct
Correct. Phishing is a social engineering attack delivered via email or other messaging platforms, where the attacker impersonates a legitimate institution like a bank to trick the recipient into revealing sensitive data. These emails often contain a spoofed 'From' address, urgent language, and a counterfeit hyperlink that leads to a fake login page designed to capture credentials. The key detection method is inspecting the full URL and sender domain, as the displayed link often differs from the actual destination.
- ✗
Vishing
Why it's wrong here
Incorrect. Vishing, or voice phishing, is conducted over telephone or VoIP systems, not through email. Attackers may spoof caller ID to appear as the bank's fraud department and use social pressure to convince victims to disclose account numbers, one-time passwords, or credit card details. Since the medium is voice rather than text, techniques like urgency impostor scams are common, but the initial vector here is email, so this answer is wrong.
- ✗
Smishing
Why it's wrong here
Incorrect. Smishing is phishing executed via SMS text messages (short message service) and sometimes mobile messaging apps. The attacker sends a text claiming fraudulent activity on the bank account and includes a shortened URL or a phone number to call, aiming to harvest credentials or install malware on the mobile device. Because the email in the scenario is not a text message, smishing does not apply, making it the wrong choice.
- ✗
Pretexting
Why it's wrong here
Incorrect. Pretexting is a social engineering technique where the attacker invents a plausible scenario (a 'pretext') to obtain information, often impersonating a coworker, service technician, or external auditor. The interaction is usually conversational via phone, in-person, or even email, but it does not necessarily involve a link or direct request for credentials; instead it seeks to build trust and gradually extract sensitive details. In this email-based credential-phishing scenario, the defining element is the malicious link, which is characteristic of phishing rather than pretexting.
Go deeper
Related to this question
Learn chapter
MFA Types for Users
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.