mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a security incident investigation, a…
During a security incident investigation, a technician finds that an attacker called the help desk, pretended to be a new employee who forgot their password, and successfully reset it. The attacker knew the employee's name and department. Which social engineering technique was used?
⚠ Common exam trap
CompTIA often tests the distinction between pretexting and phishing by emphasizing that pretexting involves direct impersonation and a fabricated scenario (often via phone or in person), while phishing relies on electronic communication like email or text messages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is a social engineering technique where the attacker fabricates a scenario (pretext) to manipulate a target into performing an action. In this case, the attacker called the help desk, assumed the identity of a new employee, and used the known details (name and department) to create a believable story, convincing the help desk to reset the password. This relies on psychological manipulation rather than technical exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering technique that primarily involves sending deceptive digital communications, such as emails (phishing), text messages (smishing), or instant messages, to trick recipients. These messages often impersonate legitimate entities to induce individuals into revealing sensitive information, clicking malicious links, or downloading malware. It typically relies on a broad, less personalized approach compared to pretexting, and does not involve a live, interactive phone call with a detailed, fabricated story.
- ✓
Pretexting
Why this is correct
Pretexting is a sophisticated social engineering tactic where an attacker creates a convincing, fabricated scenario or 'pretext' to manipulate a target into divulging specific information or performing a particular action. This often involves extensive prior research to establish a believable false identity and a compelling story, such as impersonating a high-level executive or a vendor, to gain the target's trust. The attacker's goal is to exploit human psychology and a perceived legitimate need for information, typically through direct interaction like a phone call or in-person conversation.
- ✗
Tailgating
Why it's wrong here
Tailgating, also known as piggybacking, is a physical security breach where an unauthorized individual gains entry to a restricted area by closely following an authorized person through a controlled access point without presenting their own credentials. This attack exploits human courtesy or inattention, relying on the authorized person to hold the door open or not challenge the follower. It is exclusively focused on bypassing physical access controls and does not involve any form of digital or phone-based social engineering manipulation.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing is a direct observation technique where an attacker covertly watches a person enter sensitive information, such as passwords, PINs, or credit card numbers, on a keyboard or screen. This method relies on visual proximity and the target's lack of awareness of their surroundings, often occurring in public or semi-public spaces like ATMs, cafes, or offices. It is a passive information-gathering technique that does not involve direct interaction, manipulation via phone, or the creation of a false identity.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.