220-1102 Security Practice Question
A user receives an email with an attachment titled 'Invoice_4352.zip'. The sender's email address is 'support@amaz0n-billing.com', but the user recognizes this is not the legitimate Amazon domain. The email urges the user to open the attachment to view the invoice. Which type of social engineering attack does this describe?
⚠ Common exam trap
Many exam-takers confuse 'phishing' with 'spear phishing' because the email appears to target Amazon customers, but the lack of personalization (e.g., no mention of the user's name or account details) makes it a generic phishing attempt, not a targeted spear phishing attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This is a classic phishing attack because the email uses a deceptive sender address (support@amaz0n-billing.com) that mimics a legitimate domain but contains a typo (zero instead of 'o') and a non-standard subdomain. The email urges the recipient to open a malicious attachment (Invoice_4352.zip), which is a common vector for malware delivery. Phishing is a broad social engineering technique that uses mass emails to trick users into revealing sensitive information or executing malicious actions, without targeting a specific individual or high-profile executive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing
Why this is correct
Phishing is a broad, opportunistic social engineering attack delivered via email, SMS, or messaging, using a spoofed sender address to impersonate a trusted entity. The generic 'invoice 4352' attachment is a classic mass-distributed lure that relies on urgency and curiosity to trick any recipient into opening a malicious file or entering credentials, with no personalized or researched element required.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted reconnaissance-driven attack where the sender customizes the message based on the victim's role, employer, relationships, or recent activities, often using internal terminology or contextual references to increase credibility. In this scenario, the attachment 'invoice 4352' and the generic wording show no evidence of prior recon or personalization; it could be sent to thousands of users indiscriminately, so categorizing it as spear phishing would require more specific tailoring than the prompt indicates.
- ✗
Whaling
Why it's wrong here
Whaling is a highly targeted subset of spear phishing that specifically attacks senior executives, CFOs, or other high-level personnel who can authorize large financial transfers or access sensitive corporate data. The scenario provides no information that the recipient holds an executive role, and the attachment 'invoice 4352' resembles a routine billing notification rather than a high-stakes, executive-specific lure, so there is no basis to classify it as whaling.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) uses telephone calls, voice over IP (VoIP), or voicemail messages to coax victims into revealing sensitive information or performing actions like installing remote-access software. Since the attack vector in this question is an email with an attachment, vishing cannot be the correct category; the scenario clearly points to a phishing email, not a voice-based social engineering attempt.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.