220-1102 Security Practice Question
A user receives an email that appears to be from their bank, warning of a security breach and asking them to click a link to verify their account. The link directs to a website that looks identical to the bank's login page but is a fraudulent site. The user enters their credentials, which are then stolen. Which type of social engineering attack is this?
⚠ Common exam trap
Many candidates confuse the generic nature of phishing with the personalized targeting of spear phishing, or they mistakenly think any email-based attack is automatically spear phishing because it appears to come from a known entity like a bank.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This is a classic phishing attack because the email is a generic, mass-distributed message impersonating a trusted entity (the bank) to trick the user into clicking a fraudulent link and entering credentials. Phishing typically uses broad targeting and relies on the appearance of legitimacy, unlike spear phishing which is personalized. The attack vector is email, not voice (vishing), and the fraudulent website mimics the bank's login page to harvest credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a highly targeted variant of phishing in which the attacker customizes the message using personal details such as the victim's name, position, or recent transactions to increase credibility. The scenario describes only an email that 'appears to be from their bank,' with no mention of any personalization or reconnaissance. Without that tailored context, the attack is better classified as generic phishing rather than spear phishing.
- ✓
Phishing
Why this is correct
Phishing is a broad type of social engineering attack that typically uses mass-distributed fraudulent emails mimicking trusted entities, such as a bank, to trick users into revealing credentials, installing malware, or taking harmful action. An unsolicited email that appears to come from the recipient's bank and requests sensitive information fits this definition exactly. The attack does not require any personal targeting and relies on volume and urgency to succeed.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a social engineering attack conducted over phone calls or voice-over-IP systems, where attackers impersonate legitimate organizations to extract personal information like account numbers or passwords. The attack in the scenario is delivered through email, not a voice channel, so vishing cannot be the correct classification. Even if the email contained a phone number to call, the initial vector is still email, making it phishing rather than vishing.
- ✗
Tailgating
Why it's wrong here
Tailgating is a physical security breach in which an unauthorized person follows an authorized employee through a secure door or gate without using their own access credentials. It relies on physical proximity and social pressure, not on digital communication like email. Since the described attack is entirely electronic and arrives in the user's inbox, tailgating is inapplicable to this scenario.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.