220-1102 Phishing uses email to trick victims. Practice Question
A user receives an email that appears to be from the company's Human Resources department. The email states that the user must click a link and log in to view an updated benefits package. The link leads to a website that closely resembles the company's internal portal but is actually a fake page. When the user enters their credentials, the information is captured by an attacker. Which type of social engineering attack is this?
⚠ Common exam trap
It's easy for candidates to confuse the delivery method (email vs. voice vs. SMS) and incorrectly choose vishing or smishing, but the core differentiator is the communication channel used to deliver the malicious link.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This attack uses email as the delivery vector, directing the user to a fraudulent website that mimics a legitimate internal portal to harvest credentials. This matches the definition of phishing, which is a social engineering technique that uses electronic communication (typically email) to trick users into revealing sensitive information. Unlike vishing (voice) or smishing (SMS), the attack here relies on a deceptive email and fake login page.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing is incorrectly identified because it uses voice communication, such as telephone calls, VoIP, or voicemail, to deceive victims into disclosing sensitive information. Attackers often spoof caller ID and pose as IT support or bank representatives. Since the described attack was delivered via email, the medium does not match vishing's voice-based vector, making it the wrong classification.
- ✗
Smishing
Why it's wrong here
Smishing is the wrong answer because it relies on SMS/text messages to deliver a deceptive link or request, often using short codes or spoofed phone numbers. The scenario explicitly states the attack came via email, so the delivery channel is incompatible with smishing. While both smishing and the described attack aim to harvest credentials, smishing's SMS vector distinguishes it from email-based phishing.
- ✓
Phishing
Why this is correct
Phishing is the correct classification. The attacker sent an email impersonating the company's HR department and directed the user to a fraudulent website designed to steal login credentials. This is classic credential-harvesting phishing, which often uses urgent language, a spoofed sender address, and a URL that resembles a legitimate sign-in page. Phishing is specifically an email-borne social engineering attack, matching every detail in the scenario.
- ✗
Tailgating
Why it's wrong here
Tailgating is a physical security attack in which an unauthorized person follows an authorized individual through a controlled entry point, such as a badge-protected door, without presenting their own credentials. It relies on in-person presence and social engineering, not on email or remote digital communication. Because the scenario describes an online email-based credential theft attempt, tailgating is completely unrelated and therefore incorrect.
Go deeper
Related to this question
Learn chapter
MFA Types for Users
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.