Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives an email that appears to be from the company's IT department, requesting that the user click a link to verify their account password due to a security breach. The user notices the email address is from "it-support@company-update.com". Which type of social engineering attack is this?

⚠ Common exam trap

Watch out — candidates often confuse the broad term 'phishing' with the more targeted 'spear phishing' or 'whaling' because the email appears personalized to the company, but the lack of specific personal details and the generic domain indicate it is a mass phishing attempt, not a targeted one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

Phishing is a broad social engineering attack where an attacker sends deceptive emails, often with a generic salutation, to trick recipients into revealing sensitive information. The email from 'it-support@company-update.com' is a classic phishing attempt because it impersonates a legitimate entity (the IT department) and uses a suspicious domain that does not match the company's actual domain, targeting a wide audience rather than a specific individual.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Phishing

    Why this is correct

    Phishing is a broad, untargeted social-engineering attack that uses deceptive emails to trick recipients into disclosing credentials, installing malware, or transferring funds. The email appears to originate from a trusted source, such as the user's own company, which is a hallmark of generic phishing. Because the scenario describes a mass-distributed email without personalization or a specific high-value victim, it fits the umbrella definition of phishing.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing is a highly customized form of phishing that relies on reconnaissance to target a specific individual or role (e.g., the finance manager) using personal or professional details. The email in the question is described as appearing to be from the company to a general user, with no indication of prior research or tailored content. Since no unique identifiers, such as the recipient's name, job title, or recent activity, are mentioned, this is not spear phishing.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is a targeted phishing attack aimed at senior executives or C-suite individuals, such as CEOs or CFOs, often using authority-based persuasion or legal/urgent language to bypass checks. There is no evidence in the scenario that the recipient is an executive or that the email contains executive-specific lures like tax documents or subpoenas. Without any such targeting, the attack is not whaling but rather a general phishing campaign.

  • ✗

    Vishing

    Why it's wrong here

    Vishing (voice phishing) is a social-engineering technique that uses telephone calls, VoIP, or voice messaging to impersonate a legitimate entity and extract sensitive information, such as credit card numbers or passwords. The attack vector here is explicitly an email, not a phone call, so any voice-based manipulation is irrelevant. Thus, while vishing might share deceptive intent, the delivery channel completely disqualifies it in this context.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.