220-1102 Security Practice Question
A user receives an email that appears to be from the company's HR department asking the user to click a link and enter their login credentials to view an updated benefits statement. The user suspects this is a phishing attempt. Which characteristic of the email most strongly indicates a phishing attack?
⚠ Common exam trap
CompTIA often tests the concept that while multiple indicators may be present, the combination of a direct request for credentials and a sense of urgency is the most definitive sign of a phishing attack, not just the presence of a spoofed domain or poor grammar.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email asks the recipient to click a link and enter their username and password immediately to avoid losing benefits.
The email creates a false sense of urgency by threatening loss of benefits unless the user acts immediately, which is a classic social engineering tactic used in phishing attacks. This urgency bypasses rational decision-making and pressures the user to click the link and enter credentials, directly enabling credential harvesting. The combination of a call to action (click a link) and a request for sensitive information (login credentials) under time pressure is the strongest indicator of a phishing attempt.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The email asks the recipient to click a link and enter their username and password immediately to avoid losing benefits.
Why this is correct
This is the strongest indicator because it represents a direct attempt to harvest authentication credentials. Legitimate organizations do not send unsolicited emails requesting users to click a link and enter their username and password to avoid losing benefits. The combination of urgency and a credential-capture link is the core mechanism of phishing, making it the clear, intentional sign of malicious activity.
- ✗
The email contains a generic greeting like 'Dear Employee' instead of the recipient's name.
Why it's wrong here
A generic greeting is a common heuristic in phishing detection, but it is not definitive. Legitimate mass emails, such as HR announcements or notifications from mailing lists, may use impersonal salutations due to privacy settings or list personalization failures. Moreover, sophisticated phishing campaigns can obtain and insert employees' names, making this indicator unreliable on its own.
- ✗
The email has a few spelling and grammar errors.
Why it's wrong here
Spelling and grammar errors are weak signals because they are not consistently present in phishing emails. Modern phishing kits, machine translation tools, and AI-generated content can produce emails with flawless grammar, while legitimate internal communications may contain typos. Relying on this indicator alone would yield many false negatives and false positives, so it cannot serve as the primary evidence of phishing.
- ✗
The email is sent from an address that looks similar to the company's HR domain but with a slight misspelling.
Why it's wrong here
A look-alike domain with a slight misspelling is a significant technical red flag, as it indicates domain spoofing or typosquatting. However, it is circumstantial: the same technique could be used for other malicious purposes, such as malware distribution or brand abuse, and it does not itself prove the intent to steal credentials. The request to enter credentials directly into a link is a more explicit and actionable demonstration of phishing intent.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.