Courseiva
Security →mediumMultiple Choice

220-1102 Phishing uses email to trick victims. Practice Question

A user receives an email that appears to be from the company's Human Resources department. The email states that the user must click a link and log in to view an updated benefits package. The link leads to a website that closely resembles the company's internal portal but is actually a fake page. When the user enters their credentials, the information is captured by an attacker. Which type of social engineering attack is this?

⚠ Common exam trap

It's easy for candidates to confuse the delivery method (email vs. voice vs. SMS) and incorrectly choose vishing or smishing, but the core differentiator is the communication channel used to deliver the malicious link.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

This attack uses email as the delivery vector, directing the user to a fraudulent website that mimics a legitimate internal portal to harvest credentials. This matches the definition of phishing, which is a social engineering technique that uses electronic communication (typically email) to trick users into revealing sensitive information. Unlike vishing (voice) or smishing (SMS), the attack here relies on a deceptive email and fake login page.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vishing

    Why it's wrong here

    Vishing is incorrectly identified because it uses voice communication, such as telephone calls, VoIP, or voicemail, to deceive victims into disclosing sensitive information. Attackers often spoof caller ID and pose as IT support or bank representatives. Since the described attack was delivered via email, the medium does not match vishing's voice-based vector, making it the wrong classification.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is the wrong answer because it relies on SMS/text messages to deliver a deceptive link or request, often using short codes or spoofed phone numbers. The scenario explicitly states the attack came via email, so the delivery channel is incompatible with smishing. While both smishing and the described attack aim to harvest credentials, smishing's SMS vector distinguishes it from email-based phishing.

  • ✓

    Phishing

    Why this is correct

    Phishing is the correct classification. The attacker sent an email impersonating the company's HR department and directed the user to a fraudulent website designed to steal login credentials. This is classic credential-harvesting phishing, which often uses urgent language, a spoofed sender address, and a URL that resembles a legitimate sign-in page. Phishing is specifically an email-borne social engineering attack, matching every detail in the scenario.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is a physical security attack in which an unauthorized person follows an authorized individual through a controlled entry point, such as a badge-protected door, without presenting their own credentials. It relies on in-person presence and social engineering, not on email or remote digital communication. Because the scenario describes an online email-based credential theft attempt, tailgating is completely unrelated and therefore incorrect.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.