Courseiva
Security →mediumMultiple Choice

220-1102 Practice Question: Phishing uses deceptive emails to trick users.

A user receives an email that appears to be from their bank, warning about a fraudulent transaction. The email contains an attachment named 'Statement.docm'. When the user attempts to open the attachment, Windows Defender detects and quarantines a Trojan. Which of the following BEST describes the attack vector that was prevented?

⚠ Common exam trap

Many candidates confuse 'phishing with a malicious macro' with 'spear phishing' because both involve email, but spear phishing requires targeted personalization, which is absent in this generic bank warning scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing with a malicious macro

The email is a phishing attempt that uses social engineering to trick the user into opening an attachment. The attachment is a .docm file, which is a Word document that can contain macros. Windows Defender detected a Trojan, which is a type of malware often delivered via malicious macros. This attack vector is specifically phishing with a malicious macro, as the macro code executes when the document is opened.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Phishing with a malicious macro

    Why this is correct

    The .docm attachment is a Word Macro-Enabled Document, and the email is a classic phishing lure impersonating a trusted financial institution. Malicious macros are embedded VBA scripts that execute when the user enables content, delivering malware or establishing persistence. This combination of social engineering and a macro-laden attachment is precisely what makes 'Phishing with a malicious macro' the correct classification.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware is a specific type of malware that encrypts files or systems and demands payment, but the question describes the attack's delivery mechanism rather than the eventual payload. The email attachment is the vector, and while it could carry ransomware, there is no evidence of file encryption or a ransom demand in the scenario. Therefore, labeling the entire event as ransomware is too broad and ignores the more accurate phishing-with-macro descriptor.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing is a targeted form of phishing that uses personalized details about a specific individual or organization to increase credibility. The scenario describes a generic bank fraud alert, likely sent to many recipients, with no customization or reconnaissance indicating the attacker knew the user. Thus, although the email is phishing, it is not spear phishing, and the correct answer must identify the macro attachment as the key malicious component.

  • ✗

    Vishing

    Why it's wrong here

    Vishing relies on voice calls to extract sensitive information, but the attack in the stem was delivered via an email attachment containing a Trojan. The correct vector is a phishing email with a malicious macro-enabled document, which vishing cannot replicate because it lacks an email or file-based payload. Vishing is tempting because both attacks use social engineering to impersonate a trusted entity, and a vishing scenario would involve a caller pressuring the user to disclose credentials or install software over the phone.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.