Courseiva
mediumMultiple Choice

220-1102 Practice Question: A user receives an email with a link that appears…

A user receives an email with a link that appears to be from their bank, asking them to verify their account. The link leads to a page that looks exactly like the bank's login page. What type of attack is this?

⚠ Common exam trap

CompTIA often tests the distinction between phishing and man-in-the-middle attacks by presenting a scenario where the user is tricked into voluntarily providing credentials on a fake site, which is phishing, not an active interception of network traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A phishing attack.

This scenario describes a phishing attack, where the attacker sends a deceptive email impersonating a trusted entity (the bank) to trick the user into clicking a malicious link. The link leads to a fraudulent website that mimics the legitimate bank login page, designed to capture the user's credentials. Phishing exploits social engineering rather than technical vulnerabilities, relying on the user's trust and inattention to detail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A man-in-the-middle attack.

    Why it's wrong here

    A man-in-the-middle attack intercepts and relays traffic between two parties who believe they communicate directly. This scenario involves no interception or relay; the user simply visits a counterfeit page. MitM would fit if an attacker proxied the genuine bank session to capture credentials.

  • ✓

    A phishing attack.

    Why this is correct

    Phishing deceives the recipient into trusting a spoofed message and surrendering credentials on a counterfeit login page. The lookalike bank page and the verification request satisfy the scenario's defining constraint: credential harvesting through social engineering rather than malware or network exploitation.

  • ✗

    A ransomware attack.

    Why it's wrong here

    Ransomware encrypts files and demands payment for decryption keys; nothing here encrypts or locks data. The email merely lures the user to a credential-harvesting page. Ransomware would be correct if the attachment or link installed encrypting malware that held the user's files hostage.

  • ✗

    A cross-site scripting (XSS) attack.

    Why it's wrong here

    XSS injects malicious scripts into websites; this scenario is a social engineering attempt via email.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.