220-1102 Security Practice Question
A user receives an email that appears to be from their bank, asking them to click a link and verify their account information due to suspicious activity. The email address is slightly misspelled (e.g., 'support@bankk.com' instead of 'support@bank.com'). Which type of social engineering attack is this?
⚠ Common exam trap
Candidates often confuse the misspelled domain with a targeted attack, but the lack of personalization (e.g., no use of the recipient's name or account number) clearly distinguishes this as generic phishing, not spear phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This is a classic example of a phishing attack because the email is a mass, unsolicited message that impersonates a legitimate entity (the bank) to trick the recipient into revealing sensitive information. The misspelled sender address ('support@bankk.com') is a common indicator of a generic phishing campaign, not a targeted one. Phishing attacks rely on volume and social engineering rather than personalized reconnaissance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted attack where the attacker customizes the message using reconnaissance about the recipient — such as recent transactions, colleague names, or job role — to increase credibility. In this scenario, the email is described as 'appearing to be from their bank' without any indication of personalization or prior research, and it is implied to be a broad, generic campaign. The absence of individualized content makes spear phishing an incorrect classification.
- ✓
Phishing
Why this is correct
This is a textbook example of phishing: an unsolicited email that impersonates a trusted institution, creates a false sense of urgency, and embeds a malicious link to a spoofed website designed to capture login credentials. Unlike spear phishing, the attack is sent en masse to many users, relying on volume rather than personalization. Phishing is the broad category for any social-engineering attempt conducted via email that tricks victims into revealing sensitive information.
- ✗
Whaling
Why it's wrong here
Whaling is a specialized form of spear phishing that exclusively targets C-level executives, financial officers, or other high-value individuals who have authority to transfer funds or approve large financial transactions. The scenario gives no indication that the user occupies such a senior position; it simply describes an ordinary email user receiving a bank notification. Whaling would require both personalization and a high-ranking victim, neither of which is present here.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, exploits the telephone system rather than email, with attackers using VoIP and caller ID spoofing to pose as legitimate organizations and trick victims into disclosing card numbers or one-time passwords. Because the described attack arrives via email and contains a link (a quintessentially email-based vector), vishing cannot be the correct answer. The distinction is purely the communication channel used for the social-engineering attempt.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user receives an email that appears to be from their bank, warning of a security breach and asking them to click a link to verify their account. The link directs to a website that looks identical to the bank's login page but is a fraudulent site. The user enters their credentials, which are then stolen. Which type of social engineering attack is this?
easy- A.Spear phishing
- ✓ B.Phishing
- C.Vishing
- D.Tailgating
Why B: This is a classic phishing attack because the email is a generic, mass-distributed message impersonating a trusted entity (the bank) to trick the user into clicking a fraudulent link and entering credentials. Phishing typically uses broad targeting and relies on the appearance of legitimacy, unlike spear phishing which is personalized. The attack vector is email, not voice (vishing), and the fraudulent website mimics the bank's login page to harvest credentials.
Variation 2. A user receives an email that appears to be from their bank, asking them to verify their account by clicking a link that leads to a fake login page. The user enters their credentials, which are then stolen. What type of attack is this?
medium- ✓ A.Phishing
- B.Vishing
- C.Smishing
- D.Whaling
Why A: This is a classic phishing attack because the user received a deceptive email impersonating a trusted entity (their bank) and was tricked into entering credentials on a fake login page. Phishing specifically uses email as the delivery vector for social engineering, which matches the scenario exactly.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.