Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security administrator notices that several employees have plugged in USB drives they received in the mail into their work computers, resulting in malware infections. The USB drives were labeled "Employee Bonus Information." What type of social engineering attack does this describe?

⚠ Common exam trap

A common mix-up: candidates confuse baiting with phishing because both involve deception, but baiting specifically relies on a physical or digital 'bait' (like a USB drive or free download) rather than a fraudulent message requesting information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Baiting

C is correct because baiting is a social engineering attack that lures victims with a promise of a reward (e.g., 'Employee Bonus Information') to trigger a specific action—plugging in a USB drive. The malware then executes automatically via autorun.inf or a malicious executable, compromising the workstation. This directly matches the scenario where physical media is used as the delivery mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting is a digital or telephony social-engineering attack in which the attacker impersonates authority figures (e.g., IT support, law enforcement) and invents a fictional scenario to lure the victim into revealing sensitive credentials or performing a specific action. In this scenario, the attack vector is an unattended physical USB drive, not a fabricated interaction between a live attacker and a victim. Pretexting would require back-and-forth communication and trust-building, whereas a USB bait attack has no direct interpersonal exchange, so it does not fit the observed behavior.

  • ✗

    Tailgating

    Why it's wrong here

    Tailgating is a physical security breach that occurs when an unauthorized person follows an authorized employee through a secured door or entry checkpoint, sometimes by pretending to have forgotten their badge. The question describes employees plugging in USB drives they received, which is a lure-based attack, not an attempt to gain entry into a restricted area. Tailgating depends on surreptitious presence at a physical boundary and authorized access, not on distributing or using malicious storage media.

  • ✓

    Baiting

    Why this is correct

    Baiting is the correct social engineering technique because it relies on leaving a tempting, often deliberately labeled physical device—such as a USB drive marked 'Confidential' or 'Bonus'—in a location where victims will find it and plug it in. Once connected, the drive may contain malware, an autorun script, or a HID emulator like a Raspberry Pi Zero that injects keystrokes to compromise the host. Unlike pretexting or phishing, baiting requires no direct interaction or fabricated communication; the attacker simply waits for the victim's curiosity to trigger the execution.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social engineering method delivered through electronic channels such as email, text messages, or fake websites, and aims to trick users into revealing credentials, clicking malicious links, or downloading malicious attachments. The scenario here specifically involves physical USB drives, which are hardware-based bait, not a message-based lure; there is no spoofed sender or deceptive URL involved. Phishing typically targets the user's information via a communication channel rather than relying on the user to insert an unattended physical device.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.