Courseiva
easyMultiple Choice

220-1102 Practice Question: An employee finds a USB drive labeled 'Employee…

An employee finds a USB drive labeled 'Employee Salary Info Q4' in the parking lot. Out of curiosity, they plug it into their work computer to see the contents. What type of social engineering attack is this an example of?

⚠ Common exam trap

CompTIA A+ often tests the distinction between baiting and phishing by emphasizing that baiting involves a physical lure (like a USB drive) while phishing is purely digital, causing candidates to confuse the two when the attack involves a digital payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Baiting

Baiting is a social engineering attack that exploits human curiosity or greed by offering something enticing, such as a USB drive labeled 'Employee Salary Info Q4.' When the employee plugs the USB into their work computer, they may inadvertently install malware (e.g., a keylogger or backdoor) that compromises the system. This attack relies on physical media as the delivery vector, distinguishing it from other social engineering methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing delivers a fraudulent message, usually email, luring the recipient to click a link or open an attachment; no message is sent. It would be correct if the employee received a deceptive email, not when they find and insert a dropped USB drive themselves.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is physically following an authorised person through a secured door without credentials; no doorway or physical access control is involved here. It would be correct if the attacker walked in behind a badge-holder, not when a dropped USB is plugged in.

  • ✓

    Baiting

    Why this is correct

    Baiting exploits curiosity by leaving physical media, such as a labelled USB drive, for a victim to plug in, delivering malware or enabling credential theft. The salary-labelled drive in the car park is a textbook baiting lure.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is inventing a false scenario to manipulate a victim into divulging information or performing an action, typically via conversation. It would apply if someone phoned claiming to be IT and requested credentials; here the lure is a physical device, not a fabricated spoken narrative.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.