220-1102 Security Practice Question
A user reports receiving multiple emails that appear to be from a colleague asking the user to wire money urgently for a business deal. The emails have slight spelling errors, and the sender's email address is subtly different from the colleague's real address. Which type of social engineering attack is this?
⚠ Common exam trap
A common mix-up: candidates confuse spear phishing with generic phishing because both use email, but the key differentiator is the targeted, personalized nature of spear phishing versus the mass, untargeted distribution of phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spear phishing
This is spear phishing because the attack is targeted: the emails impersonate a specific colleague and reference a plausible business context, making it highly personalized. Unlike generic phishing, spear phishing uses reconnaissance to craft messages that appear legitimate to a particular individual or organization, increasing the likelihood of success.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Generic phishing campaigns cast a wide net, blasting the same template to thousands of recipients with no prior research. A message that references a named colleague and arrives with a recognizable conversational thread indicates attacker reconnaissance, which is the hallmark of targeted phishing rather than standard bulk phishing. Thus, while phishing is the broad category, it is not the precise term for this personalized attack.
- ✓
Spear phishing
Why this is correct
Spear phishing is a socially engineered email tailored using victim-specific details, such as the sender's real name, job role, or recent projects, to bypass suspicion. Here, the attacker impersonates a trusted colleague and leverages urgency—possibly spoofing the reply chain—to manipulate the recipient into immediate action. Because the targeting is individualized and the pretext is credible, this exactly matches spear phishing's definition.
- ✗
Whaling
Why it's wrong here
Whaling is a form of spear phishing aimed exclusively at senior executives like CEOs or CFOs, where the attacker seeks to exploit their authority over large financial transactions or sensitive corporate data. The scenario describes an ordinary employee receiving a colleague-looking email; without any indication of C-suite position or high-value financial stakes, it does not meet the criterion of whaling. It is the victim's rank that distinguishes whaling, not the technique itself.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) is executed over phone calls or VoIP, using interactive voice responses or live callers to harvest credentials or payment information. The attack described uses email as the delivery mechanism, with written text and possibly a malicious link or attachment. Since the medium is not voice, vishing is categorically inapplicable to this scenario.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An employee receives an email that appears to be from the company's CEO, asking the employee to urgently purchase gift cards for a client and reply with the redemption codes. The email address is slightly misspelled (e.g., ceo@cornpany.com instead of ceo@company.com). The employee complies. Which type of social engineering attack is this?
medium- ✓ A.Spear phishing
- B.Vishing
- C.Pharming
- D.Tailgating
Why A: This is spear phishing because the email is crafted to impersonate a specific high-ranking individual (the CEO) and is directed at a specific employee, using urgent language and a plausible request. The misspelled sender domain (ceo@cornpany.com) is a common social engineering technique to trick the recipient into overlooking the header. While generic phishing casts a wide net, spear phishing is targeted and personalized, which matches the CEO impersonation and gift-card request described.
Variation 2. A user receives an email that appears to be from the IT department asking them to verify their account by clicking a link and entering their password. The email has a sense of urgency, stating the account will be disabled within 24 hours. Which type of social engineering attack is this?
medium- ✓ A.Spear phishing
- B.Vishing
- C.Tailgating
- D.Shoulder surfing
Why A: This is spear phishing because the email is directed at a specific user (the recipient) and impersonates the IT department to appear legitimate. It uses a sense of urgency and a spoofed sender to trick the user into revealing credentials. Unlike generic phishing, which targets large numbers of unrelated people, spear phishing is focused on a specific individual or group within an organization.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.