Home > Glossary > CompTIA PenTest+ > Vishing (Voice Phishing)

📖 What is Vishing (Voice Phishing)?

Vishing (Voice Phishing) is a social engineering attack that uses voice communication, such as phone calls or VoIP, to deceive victims into revealing sensitive information. Attackers often use urgency or impersonate authority figures, like bank officials or IT support, to manipulate the target.

🥋 Sensei Says:

"Be aware of 'deepfake' audio technology, which is increasingly used in advanced vishing attacks to impersonate a known executive's voice."

📚 Certification: CompTIA PenTest+ (PT0-002)

🔑 What are the Key Concepts of Vishing (Voice Phishing)?

  • Caller ID Spoofing: Attackers manipulate the caller ID to appear as a trusted organization, increasing the likelihood that the victim will answer and trust the caller.
  • Psychological Triggers: Vishing relies on urgency, fear, or authority—such as pretending to be a government agent—to pressure victims into making quick, irrational decisions.
  • IVR Manipulation: Some vishing attacks use automated Interactive Voice Response systems to trick users into entering sensitive data, like PINs, via their phone keypad.
  • VoIP Integration: Voice over IP allows attackers to scale campaigns globally, automate calls using bots, and easily mask their true geographic location from victims.
  • Deepfake Audio: Advanced attacks use AI-generated voice cloning to mimic specific executives, making the impersonation highly convincing for authorizing fraudulent financial transactions.

🎯 How does Vishing (Voice Phishing) appear on the PT0-002 Exam?

You may be asked to identify the specific social engineering technique used when an attacker calls an employee pretending to be a help desk technician to steal credentials, focusing on the voice-based delivery method.

A scenario might describe an attacker using a spoofed phone number to impersonate a bank representative, urging a target to provide a one-time password (OTP) over the phone to 'verify' their identity.

Expect questions where you must distinguish between vishing, smishing, and phishing based on the medium used to deliver the deceptive message to the target during a social engineering engagement.

❓ Frequently Asked Questions

How does vishing differ from smishing in a PenTest+ context?

Vishing utilizes voice communication, such as phone calls or VoIP, whereas smishing specifically uses SMS or text messages. While both are social engineering, the exam requires you to distinguish them by the delivery medium.


What is the role of 'pretexting' in a vishing attack?

Pretexting is the act of creating a fabricated scenario to establish trust. In vishing, the pretext is the story the attacker tells—such as a security breach—to justify requesting sensitive information.

Related Terms from CompTIA PenTest+

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Vishing (Voice Phishing)? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium