Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

An employee receives an email that appears to be from the company's HR department, requesting that they click a link to verify their login credentials for a new payroll system. The link leads to a fraudulent website that captures the employee's username and password. Which type of social engineering attack is this?

⚠ Common exam trap

A common mix-up: candidates confuse spear phishing with phishing because the email is addressed to 'an employee' and appears targeted to the company, but the lack of personalization (e.g., using the employee's name or specific HR details) makes it a generic phishing attempt, not spear phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

This attack is phishing because it involves a mass, unsolicited email that impersonates a legitimate entity (HR) to trick the recipient into clicking a fraudulent link and divulging credentials. The email is not personalized with the employee's name or specific details, which distinguishes it from spear phishing. The goal is to capture login information via a fake website, a classic phishing technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spear phishing

    Why it's wrong here

    The email is directed at employees broadly and uses generic HR language, not the recipient's name, job title, recent activity, or other personal details. Spear phishing requires attacker research and message customization to deceive a specific high-value target, so a mass-distributed, non-personalized credential lure is better classified as ordinary phishing.

  • ✓

    Phishing

    Why this is correct

    This attack impersonates the Human Resources department and uses a fraudulent link to collect credentials from recipients. It is classic broad-net phishing: the attacker relies on volume, urgency, and a trusted-sender disguise rather than prior reconnaissance, and the victim's act of entering login information on the fake page completes the attack.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is an interactive social-engineering technique where the attacker builds a false scenario or identity, often during a phone call or in-person exchange, to directly extract information from the victim. This scenario is email-based and uses a malicious hyperlink to a fake login page, so no live actor is inventing a believable narrative, which makes it distinct from a pretexting attempt.

  • ✗

    Pharming

    Why it's wrong here

    Pharming is a technical attack that quietly redirects a user to a fraudulent website by poisoning DNS resolution, modifying the hosts file, or exploiting a router, with no email or deceptive link involved. Because the incident starts with a phishing email containing a malicious link, the user is lured by social engineering rather than having their legitimate web traffic silently rerouted, so pharming does not match this attack.

Go deeper

Related to this question

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user receives an email that appears to come from the company's CEO, asking the user to purchase several gift cards for a client appreciation event and to reply with the activation codes. The email address is similar to the CEO's but has an extra character. Which type of social engineering attack is this?

easy
  • ✓ A.Phishing
  • B.Vishing
  • C.Smishing
  • D.Pretexting

Why A: This is phishing because the attacker uses a deceptive email that mimics a legitimate source (the CEO) to trick the user into revealing sensitive information (gift card activation codes). The extra character in the email address is a classic spoofing technique, making it a subtype often called spear phishing or CEO fraud. Phishing specifically covers email-based social engineering attacks that request credentials, financial data, or other private information.

Variation 2. A user receives an email that appears to be from the company's IT department, requesting that the user click a link to verify their account password due to a security breach. The user notices the email address is from "it-support@company-update.com". Which type of social engineering attack is this?

medium
  • ✓ A.Phishing
  • B.Spear phishing
  • C.Whaling
  • D.Vishing

Why A: Phishing is a broad social engineering attack where an attacker sends deceptive emails, often with a generic salutation, to trick recipients into revealing sensitive information. The email from 'it-support@company-update.com' is a classic phishing attempt because it impersonates a legitimate entity (the IT department) and uses a suspicious domain that does not match the company's actual domain, targeting a wide audience rather than a specific individual.

Variation 3. A user receives an email that appears to be from the company's IT department, stating that their email password will expire in 24 hours and asks them to click a link to renew it. The link goes to a page that looks exactly like the company's login portal, but the URL is slightly different. The user enters their credentials. Which type of social engineering attack has occurred?

easy
  • ✓ A.Phishing
  • B.Spear phishing
  • C.Whaling
  • D.Vishing

Why A: This is a classic phishing attack because the email is a generic, mass-distributed message impersonating the IT department to trick the user into revealing credentials. The attack does not target a specific individual (spear phishing) or a high-profile executive (whaling), and it uses a link rather than a phone call (vishing). The fake login page with a slightly different URL is a hallmark of phishing, often leveraging URL obfuscation or homograph attacks.

Variation 4. A user receives an email that appears to be from the company's Human Resources department. The email states that the user must click a link and log in to view an updated benefits package. The link leads to a website that closely resembles the company's internal portal but is actually a fake page. When the user enters their credentials, the information is captured by an attacker. Which type of social engineering attack is this?

medium
  • A.Vishing
  • B.Smishing
  • ✓ C.Phishing
  • D.Tailgating

Why C: This attack uses email as the delivery vector, directing the user to a fraudulent website that mimics a legitimate internal portal to harvest credentials. This matches the definition of phishing, which is a social engineering technique that uses electronic communication (typically email) to trick users into revealing sensitive information. Unlike vishing (voice) or smishing (SMS), the attack here relies on a deceptive email and fake login page.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.