mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: That they clicked a link in a text message that…
A user reports that they clicked a link in a text message that appeared to be from their bank, warning of suspicious activity. The link led to a realistic-looking login page, but the user realized it was fake after entering their credentials. What type of social engineering attack is this?
⚠ Common exam trap
The CompTIA A+ exam often tests the distinction between smishing and vishing by focusing on the delivery method (SMS vs. voice), so candidates mistakenly choose vishing when they see 'text message' but focus on the 'warning of suspicious activity' pretext rather than the medium.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
Smishing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) containing a link to a fraudulent website. The user received the message on their mobile device, clicked the link, and entered credentials on a fake login page, which is the hallmark of smishing. Unlike vishing (voice phishing), this attack uses text-based messaging to deliver the malicious link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack conducted exclusively over telephone calls. Attackers use deceptive voice messages or live conversations to trick individuals into divulging sensitive information, such as bank account details, credit card numbers, or login credentials, by impersonating legitimate entities. Since the user in the question clicked a link in a text message, rather than interacting via a voice call, vishing is not the correct term for this specific attack vector.
- ✓
Smishing
Why this is correct
Smishing is a specific form of phishing that leverages Short Message Service (SMS), commonly known as text messages, to deliver malicious links or solicit sensitive information. In a smishing attack, users receive a deceptive text message, often impersonating a legitimate entity like a bank or delivery service, which prompts them to click a fraudulent link. This link typically leads to a fake website designed to capture credentials or install malware, directly matching the scenario where a user clicked a link in a text message.
- ✗
Pharming
Why it's wrong here
Pharming is a cyberattack that redirects users from legitimate websites to fraudulent ones without their explicit knowledge or interaction, often by manipulating Domain Name System (DNS) resolution or modifying local host files. Unlike phishing, pharming does not require the user to click a malicious link in an email or text message; instead, the redirection occurs automatically when the user attempts to access a legitimate site. The scenario described, where the user actively clicked a link, indicates an explicit user interaction not characteristic of pharming's passive redirection.
- ✗
Pretexting
Why it's wrong here
Pretexting is a social engineering technique where an attacker creates a fabricated scenario, or "pretext," to manipulate a victim into divulging information or performing an action. This often involves impersonating someone in authority or a trusted individual to gain the victim's confidence through a convincing story, typically over the phone or in person. While a text message might be part of a broader pretexting scheme, the core of pretexting is the elaborate narrative and deception to extract information, whereas the question specifically highlights clicking a malicious link in a text message as the primary attack vector.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.