Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives an email that appears to be from the company's payroll department. The email states that all employees must click a link and log in with their corporate credentials to verify their direct deposit information. The technician notices the sender's email address is 'payroll@cornpany.com' (with 'rn' instead of 'm'). Which type of social engineering attack is this?

⚠ Common exam trap

The 220-1102 exam often tests the distinction between phishing and spear phishing by including a generic email with a spoofed domain, where candidates mistakenly choose spear phishing because the email appears to come from a specific department (payroll), but the lack of personalization makes it standard phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

This is a phishing attack because the email is a mass, unsolicited message that uses a deceptive sender address ('cornpany.com' with 'rn' instead of 'm') to trick recipients into revealing corporate credentials. Phishing typically targets a broad audience with generic lures, unlike spear phishing or whaling which are more targeted. The attack relies on social engineering via email, not voice (vishing).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing is a targeted attack aimed at a specific individual or organization, not a broad email to all employees. It relies on reconnaissance to customize the email with the victim's name, role, or other personal details to increase credibility. In contrast, a general company-wide email that looks official but isn't personalized is more typical of a standard phishing attempt, not spear phishing.

  • ✗

    Whaling

    Why it's wrong here

    Whaling targets executives or high-profile individuals, not the general employee base. A whaling email is a specific form of phishing that goes after 'big fish' like CEOs or CFOs, often using personalized, high-stakes content such as legal threats or urgent wire transfers. Since the scenario describes a generic user receiving an email that appears to be from the company, it lacks the high-level targeting characteristic of whaling.

  • ✓

    Phishing

    Why this is correct

    Phishing is a broad social engineering attack using fraudulent emails that mimic legitimate organizations to steal credentials or personal data. It is sent to many users at once, relying on volume and the appearance of authenticity to trick recipients. The email in the question fits this definition: it appears to be from the company and is likely intended to deceive the recipient into taking an action like clicking a link or entering login details. This is the correct answer.

  • ✗

    Vishing

    Why it's wrong here

    Vishing (voice phishing) is performed over the phone, not via email. It uses voice calls or VoIP to impersonate legitimate entities and extract sensitive information, often with automated or live callers. Since the described attack is an email, vishing is not applicable here.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user reports receiving an email that appears to be from the company's HR department, asking employees to click a link to verify their login credentials for a new benefits portal. The email contains the company logo and the user's full name. The user clicked the link and entered their username and password. Which type of social engineering attack has occurred?

easy
  • A.Vishing
  • ✓ B.Phishing
  • C.Tailgating
  • D.Shoulder surfing

Why B: The user received an email that appears legitimate (company logo, personal details) and was tricked into clicking a link and entering credentials. This is a classic phishing attack, specifically a form of email-based social engineering that targets login credentials. Phishing relies on deceptive messages to bypass technical controls by exploiting human trust.

Variation 2. A user reports receiving an email that appears to be from a well-known shipping company. The email states that a package delivery could not be completed and asks the user to click a link to reschedule. The user clicks the link, which opens a webpage that looks like the shipping company's login page, and enters their email address and password. Which type of social engineering attack has occurred?

medium
  • ✓ A.Phishing
  • B.Vishing
  • C.Spear phishing
  • D.Whaling

Why A: This is a classic phishing attack because the user received an unsolicited email impersonating a legitimate shipping company, which directed them to a fraudulent login page designed to capture their credentials. Phishing is a broad category of social engineering where attackers use deceptive messages (typically email) to trick victims into revealing sensitive information, and the generic nature of the email (not targeting a specific individual or high-profile executive) confirms it as standard phishing.

Variation 3. A user receives an email from an unknown sender with an attachment labeled 'Invoice_2024.zip'. The user opens the attachment, which contains an executable file. The user runs the executable, and the workstation starts encrypting files. Which type of social engineering attack is this?

easy
  • ✓ A.Phishing
  • B.Spear phishing
  • C.Whaling
  • D.Vishing

Why A: This is a phishing attack because the user received an unsolicited email from an unknown sender containing a malicious attachment (Invoice_2024.zip) that, when opened and executed, triggered ransomware encryption. Phishing is a broad social engineering technique that uses deceptive emails to trick recipients into performing actions like opening attachments or clicking links, without requiring any personalization or targeting of a specific individual.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.