Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

An employee receives a phone call from someone claiming to be from the IT department. The caller states there has been a security breach and asks the employee to provide their domain password to verify the account. What type of social engineering attack is this?

⚠ Common exam trap

Candidates often confuse vishing with phishing because both involve credential theft, but the key differentiator is the communication channel—vishing uses voice calls, while phishing uses email or websites.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vishing

This is a vishing (voice phishing) attack because the attacker uses a phone call to impersonate IT staff and socially engineer the victim into revealing their domain password. Unlike phishing (email) or smishing (SMS), vishing specifically leverages voice communication to bypass technical controls and exploit human trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad term for social engineering that attempts to steal credentials or sensitive data, but it is most precisely applied to email or web-based lures, such as malicious links in an email. A phone call is a voice-based medium, so "vishing" is the more specific and accurate label for an attacker phoning to extract a password. Since the question's attack vector is a live conversation, classifying it simply as phishing loses the important distinction that this is voice phishing.

  • ✓

    Vishing

    Why this is correct

    Vishing, short for voice phishing, is the technical term for social engineering performed over a telephone call. Attackers often use caller-ID spoofing and a rehearsed pretext, such as a help-desk technician, to build trust and convince the target to reveal a domain password or other confidential information. Because the employee received a phone call asking for the domain password, vishing is the exact match for this attack vector.

  • ✗

    Smishing

    Why it's wrong here

    Smishing, a portmanteau of SMS and phishing, uses text-message payloads that typically contain malicious links or attachments, and it requires the victim to interact with the message itself. Unlike a voice call, there is no live attacker on the line conducting a conversation or applying real-time pressure. The scenario describes a phone call, not an SMS delivery, so smishing is an incorrect label.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating relies on physical access deception, such as following an authorised person through a secured door, but this scenario involves a phone-based request for a domain password, which is a purely remote, credential-harvesting attack. It is tempting because tailgating is a common social engineering technique, and in a scenario where an attacker physically follows an employee into a restricted area without authentication, it would be the correct choice.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An employee receives a phone call from someone claiming to be a vendor's technical support representative. The caller says they need the employee's domain administrator password to 'apply a critical security patch'. The employee recognizes the vendor's name but is suspicious. Which type of social engineering attack is this?

hard
  • A.Phishing
  • ✓ B.Vishing
  • C.Smishing
  • D.Tailgating

Why B: B is correct because vishing (voice phishing) is a social engineering attack conducted over voice calls, where the attacker impersonates a trusted entity (here, a vendor's technical support) to manipulate the victim into divulging sensitive information like a domain administrator password. The key indicators are the phone call medium and the request for credentials under the pretext of urgency (critical security patch).

Variation 2. A user receives a phone call from an individual claiming to be from the company's IT security team. The caller states there is a breach and asks the user to verify their account by providing their username and password. Which social engineering technique is being used?

medium
  • A.Phishing
  • ✓ B.Vishing
  • C.Smishing
  • D.Tailgating

Why B: Vishing (voice phishing) is the correct answer because the attack is conducted over a phone call, where the attacker impersonates IT security to trick the user into revealing credentials. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to exploit trust and urgency.

Variation 3. A user receives a phone call from an individual claiming to be from the company's IT help desk. The caller states that there is a critical security update and asks the user for their login credentials to apply the update. Which type of social engineering attack is this?

medium
  • A.Phishing
  • ✓ B.Vishing
  • C.Smishing
  • D.Tailgating

Why B: This is a vishing (voice phishing) attack because the social engineering is conducted over a phone call, where the attacker impersonates IT help desk personnel to trick the user into revealing login credentials. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to bypass email filters and exploit human trust through direct verbal interaction.

Variation 4. A user receives a phone call from someone claiming to be from the IT help desk. The caller says there is a security problem with the user's account and asks the user to provide their password to resolve the issue. Which type of social engineering attack does this describe?

easy
  • A.Phishing
  • ✓ B.Vishing
  • C.Smishing
  • D.Pretexting

Why B: This is vishing (voice phishing) because the attack is carried out over a phone call, where the attacker impersonates IT help desk personnel to socially engineer the victim into revealing their password. Unlike phishing (email) or smishing (SMS), vishing specifically uses voice communication to bypass technical controls and exploit human trust.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.