220-1102 Security Practice Question
A user receives an email that appears to be from the company's IT department, requesting that the user click a link to verify their account password due to a security breach. The user notices the email address is from "it-support@company-update.com". Which type of social engineering attack is this?
⚠ Common exam trap
Watch out — candidates often confuse the broad term 'phishing' with the more targeted 'spear phishing' or 'whaling' because the email appears personalized to the company, but the lack of specific personal details and the generic domain indicate it is a mass phishing attempt, not a targeted one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
Phishing is a broad social engineering attack where an attacker sends deceptive emails, often with a generic salutation, to trick recipients into revealing sensitive information. The email from 'it-support@company-update.com' is a classic phishing attempt because it impersonates a legitimate entity (the IT department) and uses a suspicious domain that does not match the company's actual domain, targeting a wide audience rather than a specific individual.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing
Why this is correct
Phishing is a broad, untargeted social-engineering attack that uses deceptive emails to trick recipients into disclosing credentials, installing malware, or transferring funds. The email appears to originate from a trusted source, such as the user's own company, which is a hallmark of generic phishing. Because the scenario describes a mass-distributed email without personalization or a specific high-value victim, it fits the umbrella definition of phishing.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a highly customized form of phishing that relies on reconnaissance to target a specific individual or role (e.g., the finance manager) using personal or professional details. The email in the question is described as appearing to be from the company to a general user, with no indication of prior research or tailored content. Since no unique identifiers, such as the recipient's name, job title, or recent activity, are mentioned, this is not spear phishing.
- ✗
Whaling
Why it's wrong here
Whaling is a targeted phishing attack aimed at senior executives or C-suite individuals, such as CEOs or CFOs, often using authority-based persuasion or legal/urgent language to bypass checks. There is no evidence in the scenario that the recipient is an executive or that the email contains executive-specific lures like tax documents or subpoenas. Without any such targeting, the attack is not whaling but rather a general phishing campaign.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) is a social-engineering technique that uses telephone calls, VoIP, or voice messaging to impersonate a legitimate entity and extract sensitive information, such as credit card numbers or passwords. The attack vector here is explicitly an email, not a phone call, so any voice-based manipulation is irrelevant. Thus, while vishing might share deceptive intent, the delivery channel completely disqualifies it in this context.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.