220-1102 Spear phishing is a targeted email attack. Practice Question
A user receives an email that appears to come from the company's payroll department. The email states that the user's salary has been updated and includes an attachment named 'Salary_Review_Q1.xlsx'. The user was not expecting this email and notices that the sender's email address is 'payroll@cornpany.com' instead of 'payroll@company.com'. The email content addresses the user by their full name and references the user's correct job title. Which type of social engineering attack is this?
⚠ Common exam trap
Candidates often confuse spear phishing with pretexting because both involve research and personalization, but the key differentiator is the delivery method: spear phishing uses email with a malicious payload, while pretexting relies on verbal or written deception to extract information without an attachment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spear phishing
Spear phishing is a targeted social engineering attack where the attacker customizes the email with specific personal details (full name, correct job title) to appear legitimate. The fraudulent sender address 'payroll@cornpany.com' (typosquatting) and the unsolicited attachment are classic indicators. This differs from generic phishing because the attacker researched the victim to increase credibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, uses phone calls or VoIP to deceive users into revealing sensitive data, often by spoofing caller ID or posing as a trusted entity. Since the described attack arrives via email, it does not match the telephony-based nature of vishing. The attacker's use of the recipient's name is irrelevant to vishing, which relies on real-time voice interaction rather than a written email.
- ✓
Spear phishing
Why this is correct
Spear phishing is a targeted email-based attack in which the attacker customizes the message with personal details—such as the recipient's name, job title, or company-specific information—to increase the likelihood of the victim clicking a malicious link or opening an attachment. Unlike mass phishing, spear phishing is highly tailored and often uses internal context to bypass email filters and appear legitimate. This email's personalization and identity-based framing are hallmarks of spear phishing, making it the correct classification.
- ✗
Tailgating
Why it's wrong here
Tailgating is a physical security breach where an unauthorized person follows an authorized employee through a secured door or checkpoint, exploiting social norms of politeness to avoid swiping a badge or providing credentials. It operates entirely in the physical realm and involves direct in-person access to facilities, not email messages or remote social engineering. Therefore, tailgating cannot apply to an email-based attack, regardless of how convincingly the sender is impersonated.
- ✗
Pretexting
Why it's wrong here
Pretexting is a social engineering technique where an attacker invents a false scenario, or pretext, to persuade a victim into providing information or performing an action, and it can occur over any communication channel, including phone, in-person, or email. While this email does create a fabricated story about the company, the mere presence of a pretext does not override the fact that the delivery method is email; in security classification, the specific attack variant is determined by the vector and targeting. When a user is singled out with personal details in an email, the more precise term is spear phishing, not pretexting.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Spear phishing
Spear phishing is a targeted cyberattack in which a criminal sends a fraudulent email that appears to come from a trusted source, aiming to trick a specific person or organization into revealing sensitive data or installing malware.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.