Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives an email that appears to be from their bank, asking them to click a link and verify their account information due to suspicious activity. The email address is slightly misspelled (e.g., 'support@bankk.com' instead of 'support@bank.com'). Which type of social engineering attack is this?

⚠ Common exam trap

Candidates often confuse the misspelled domain with a targeted attack, but the lack of personalization (e.g., no use of the recipient's name or account number) clearly distinguishes this as generic phishing, not spear phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

This is a classic example of a phishing attack because the email is a mass, unsolicited message that impersonates a legitimate entity (the bank) to trick the recipient into revealing sensitive information. The misspelled sender address ('support@bankk.com') is a common indicator of a generic phishing campaign, not a targeted one. Phishing attacks rely on volume and social engineering rather than personalized reconnaissance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing is a targeted attack where the attacker customizes the message using reconnaissance about the recipient — such as recent transactions, colleague names, or job role — to increase credibility. In this scenario, the email is described as 'appearing to be from their bank' without any indication of personalization or prior research, and it is implied to be a broad, generic campaign. The absence of individualized content makes spear phishing an incorrect classification.

  • ✓

    Phishing

    Why this is correct

    This is a textbook example of phishing: an unsolicited email that impersonates a trusted institution, creates a false sense of urgency, and embeds a malicious link to a spoofed website designed to capture login credentials. Unlike spear phishing, the attack is sent en masse to many users, relying on volume rather than personalization. Phishing is the broad category for any social-engineering attempt conducted via email that tricks victims into revealing sensitive information.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is a specialized form of spear phishing that exclusively targets C-level executives, financial officers, or other high-value individuals who have authority to transfer funds or approve large financial transactions. The scenario gives no indication that the user occupies such a senior position; it simply describes an ordinary email user receiving a bank notification. Whaling would require both personalization and a high-ranking victim, neither of which is present here.

  • ✗

    Vishing

    Why it's wrong here

    Vishing, or voice phishing, exploits the telephone system rather than email, with attackers using VoIP and caller ID spoofing to pose as legitimate organizations and trick victims into disclosing card numbers or one-time passwords. Because the described attack arrives via email and contains a link (a quintessentially email-based vector), vishing cannot be the correct answer. The distinction is purely the communication channel used for the social-engineering attempt.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user receives an email that appears to be from their bank, warning of a security breach and asking them to click a link to verify their account. The link directs to a website that looks identical to the bank's login page but is a fraudulent site. The user enters their credentials, which are then stolen. Which type of social engineering attack is this?

easy
  • A.Spear phishing
  • ✓ B.Phishing
  • C.Vishing
  • D.Tailgating

Why B: This is a classic phishing attack because the email is a generic, mass-distributed message impersonating a trusted entity (the bank) to trick the user into clicking a fraudulent link and entering credentials. Phishing typically uses broad targeting and relies on the appearance of legitimacy, unlike spear phishing which is personalized. The attack vector is email, not voice (vishing), and the fraudulent website mimics the bank's login page to harvest credentials.

Variation 2. A user receives an email that appears to be from their bank, asking them to verify their account by clicking a link that leads to a fake login page. The user enters their credentials, which are then stolen. What type of attack is this?

medium
  • ✓ A.Phishing
  • B.Vishing
  • C.Smishing
  • D.Whaling

Why A: This is a classic phishing attack because the user received a deceptive email impersonating a trusted entity (their bank) and was tricked into entering credentials on a fake login page. Phishing specifically uses email as the delivery vector for social engineering, which matches the scenario exactly.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.