hardMultiple Choice
220-1102 Practice Question: During a security incident response, you discover…
During a security incident response, you discover that a user's browser has a rogue extension that exfiltrates data to a remote server. The extension was installed after the user clicked a fake update prompt on a website. What vulnerability was exploited?
⚠ Common exam trap
The A+ exam often tests the distinction between technical exploits and human-factor attacks, and the trap here is that candidates may assume any browser-related compromise must involve a technical vulnerability like a zero-day, overlooking that social engineering bypasses technical controls entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Social engineering.
The attack exploited the user's trust and lack of caution, not a technical flaw in the browser or web application. The user was tricked into installing a rogue extension by clicking a fake update prompt, which is a classic social engineering technique that manipulates human psychology rather than exploiting code vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A zero-day vulnerability in the browser.
Why it's wrong here
A zero-day is an unknown, unpatched flaw; here the user voluntarily installed the extension after a social-engineering prompt, so no browser code flaw was exploited. Zero-days are tempting because they genuinely describe undisclosed vulnerabilities, which is their real meaning in threat reporting.
- ✗
An insecure direct object reference (IDOR) vulnerability.
Why it's wrong here
IDOR occurs when an application exposes objects by user-supplied identifiers without authorisation checks; no object reference or API parameter is involved here. IDOR is tempting because it genuinely describes broken access control in web applications, which is its actual purpose.
- ✓
Social engineering.
Why this is correct
Social engineering exploits human trust rather than a software flaw, which matches the fake update prompt that tricked the user into installing the rogue extension. The browser itself was not compromised; the user's decision to click and approve installation enabled the exfiltration, satisfying the stem's requirement for the exploited vulnerability.
- ✗
A cross-site request forgery (CSRF) attack.
Why it's wrong here
CSRF forces an authenticated browser to submit unintended requests to a trusted site; it does not install extensions or exfiltrate data. CSRF is tempting because it genuinely exploits a user's existing session, which is its real purpose in web application attacks.
Go deeper
Related to this question
Learn chapter
Remote Support Tools and Techniques
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.