220-1102 Security Practice Question
An employee finds a USB flash drive in the company parking lot and inserts it into their workstation out of curiosity. Immediately, the system begins exhibiting unusual behavior, including pop-ups and slowdowns. Which type of social engineering attack is this an example of?
⚠ Common exam trap
Many exam-takers confuse baiting with phishing because both involve tricking the user, but baiting specifically relies on physical media or a tangible lure (like a USB drive), whereas phishing is purely digital.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Baiting
This is a classic example of a baiting attack, a type of social engineering where an attacker leaves a malware-infected USB flash drive in a public location (like a parking lot) to entice a victim into plugging it into their computer. When the employee inserts the drive, the system automatically executes malicious code (e.g., via autorun.inf or a malicious executable), leading to pop-ups and slowdowns. Unlike phishing or spear phishing, which rely on digital deception, baiting exploits physical curiosity and trust in found objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering technique conducted through electronic channels such as email, text messages, or fraudulent websites, where attackers masquerade as legitimate entities to trick recipients into divulging credentials or downloading malware. The scenario involves a physical USB flash drive found in a parking lot, not a digital communication vector. Therefore, phishing does not apply because the attack requires an online or electronic delivery mechanism, not a physical device.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a highly targeted form of phishing in which the attacker researches a specific individual or organization and crafts a personalized, credible email to maximize the chance of success. It relies on digital correspondence and often uses social details to bypass email filters, but it does not use physical objects as the distribution mechanism. The employee's discovery is a generic, untargeted physical lure, which is the opposite of a tailored electronic attack.
- ✓
Baiting
Why this is correct
Baiting is a social engineering attack that uses a physical or digital lure, such as a malware-infected USB drive, to exploit a victim's curiosity or greed. By leaving a labeled or unlabeled drive in a visible location, the attacker induces the finder to plug it into a corporate workstation, potentially triggering malware or credential theft. This precisely matches the described scenario of an employee discovering a flash drive in a parking lot, as the attack relies on the victim's voluntary action rather than direct manipulation.
- ✗
Tailgating
Why it's wrong here
Tailgating is a physical penetration technique where an unauthorized individual follows an authorized person through a controlled entry point, such as a badge-protected door, without providing credentials. It involves direct human presence and social pressure, not the use of an inanimate decoy device left behind. Since the employee found a USB drive rather than being followed by an intruder, tailgating is an incorrect classification.
Go deeper
Related to this question
Learn chapter
Email Security: Spam and Phishing Detection
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Universal Serial Bus
A Universal Serial Bus (USB) is a standard interface that allows you to connect devices like keyboards, mice, storage drives, and printers to a computer for data transfer and power delivery.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.