Home > Blog > CompTIA CompTIA A+ Certification Exam Core 2 > Phishing, Vishing, and Smishing: A+ Security Guide

Phishing, Vishing, and Smishing: A+ Security Guide

Deep Dive Cert Sensei Team 2031-08-11 8 min read

Social engineering types like phishing (email), vishing (voice), and smishing (SMS) manipulate human psychology to steal sensitive data. For the CompTIA A+ 220-1102 exam, you must distinguish these methods by their delivery medium and recognize common markers like artificial urgency, fear-based tactics, and suspicious sender addresses.

#CompTIA A+ #Social Engineering #Cybersecurity #220-1102

What is Phishing and How Do You Spot It?

Phishing is the most common form of social engineering you'll encounter on the A+ exam. It's essentially a digital fishing trip where the attacker throws out a wide net of fraudulent emails hoping someone bites. You need to look for specific markers: generic greetings like 'Dear Valued Customer,' poor grammar, and a sender address that almost—but not quite—matches the official domain (e.g., [email protected] instead of microsoft.com).

When you're analyzing an email, the most practical move is to hover your mouse over any link without clicking. This reveals the actual destination URL. If the link says 'Update Your Password' but points to a random string of numbers or an unrelated domain, it's a red flag. Remember, legitimate companies will rarely ask for your password or social security number via an unsolicited email. Mastering these identifiers is key to passing the security domain of the 220-1102 exam.

What Exactly is Vishing and How Does it Work?

Vishing, or 'voice phishing,' moves the attack from the inbox to the phone. Attackers use VoIP (Voice over IP) and caller ID spoofing to make it look like they are calling from a trusted source, such as your bank, the IRS, or even your company's IT help desk. They rely on the inherent trust people place in a human voice to manipulate the victim into revealing sensitive information or granting remote access to a computer.

A classic vishing scenario involves an attacker claiming there is a 'security breach' on your account and insisting you provide your MFA (Multi-Factor Authentication) code to 'verify' your identity. In reality, they are triggering a login attempt and using your code to bypass security. On the A+ exam, if the scenario mentions a phone call or voice manipulation, your mind should immediately go to vishing.

How Does Smishing Differ from Traditional Phishing?

Smishing is simply phishing via SMS (text messages). Because people tend to trust their text messages more than their email inboxes, smishing often has a higher success rate. These messages are typically short and designed to trigger an immediate reaction. You'll see things like 'Your package delivery has failed' or 'Unusual activity detected on your account' followed by a shortened URL (like bit.ly or tinyurl.com) to hide the destination.

Smishing is particularly dangerous because mobile browsers often hide the full URL, making it harder for you to spot a fake domain. The goal is almost always the same as phishing: to lead you to a credential-harvesting site or to trick you into downloading a malicious APK or profile on your device. When studying for Core 2, remember that the 'S' in smishing stands for SMS—that's the easiest way to keep these straight.

Why Do Social Engineering Attacks Use Urgency and Fear?

Attackers don't just rely on technology; they rely on psychology. The core of most social engineering types is the creation of an artificial crisis. By using urgency ('Your account will be deleted in 2 hours!') or fear ('A warrant has been issued for your arrest'), the attacker triggers a 'fight or flight' response in your brain. This effectively bypasses the logical, critical-thinking part of your mind, making you more likely to follow instructions without questioning them.

This is known as the 'Amigdala hijack.' In a professional environment, this might look like an email from the 'CEO' demanding an urgent wire transfer while they are in a meeting and cannot be reached. If you see a scenario on the exam where a user is pressured to act quickly to avoid a negative consequence, you are looking at a psychological trigger designed to facilitate a social engineering attack.

How Can You Prevent These Attacks in a Real-World Environment?

Prevention requires a multi-layered approach. From a technical standpoint, you should implement email filters that scan for known malicious signatures and use protocols like SPF (Sender Policy Framework), DKIM, and DMARC to prevent domain spoofing. Multi-Factor Authentication (MFA) is your strongest defense; even if an attacker steals a password via phishing, they still can't access the account without the second factor.

However, the human element is the weakest link. User awareness training is critical. You need to teach employees to 'trust but verify'—if they get an urgent request from a manager, they should call that manager on a known number to confirm. Regular phishing simulations can help users recognize the markers we discussed. In a real-world IT role, your job isn't just to fix the computer, but to educate the user so they don't click the link in the first place.

How Do You Master These Concepts for the A+ Exam?

Reading a textbook is a start, but you won't truly know if you're ready until you've faced exam-style questions. The CompTIA A+ 220-1102 exam loves to use scenario-based questions where you have to distinguish between very similar attacks. For example, you might be asked to identify the specific type of social engineering used when a user receives a text about a fake invoice.

To get you there, we've built a powerhouse tool at Cert Sensei. We offer 1,000 expert-curated practice questions specifically for the A+ Core 2 exam. Instead of just telling you if you're wrong, we provide detailed expert reasoning for every single answer, so you understand the 'why' behind the 'what.' Plus, our domain-level analytics show you exactly where you're struggling—whether it's security, software troubleshooting, or operational procedures—so you can stop wasting time on what you already know and focus on your weak spots.

❓ Frequently Asked Questions

What is the difference between spear phishing and whaling?

Phishing is a broad attack. Spear phishing is targeted at a specific individual or group using personal details to seem legitimate. Whaling is a form of spear phishing specifically targeting high-level executives (the 'big fish'), such as the CEO or CFO, often involving high-value financial fraud.


Can a strong spam filter stop all phishing attempts?

No filter is 100% effective. Attackers constantly evolve their tactics, using 'zero-day' phishing sites or compromising legitimate accounts to send mail. This is why technical controls must be paired with user training and MFA to create a comprehensive security posture.


What should a user do immediately after clicking a suspicious link?

The user should immediately disconnect the device from the network (Wi-Fi or Ethernet) to prevent malware from spreading or communicating with a Command and Control (C2) server. Then, they must report the incident to the IT security team and change their passwords from a known-clean device.

More from CompTIA CompTIA A+ Certification Exam Core 2

🧠

Test Your Knowledge

Ready to practice CompTIA A+ Certification Exam Core 2? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free