CompTIA A+ Core 2 (220-1202) · Section 16 of 36

Free Social Engineering Attacks, Threats, and Vulnerabilities practice questions

10 free 220-1202 questions on Social Engineering Attacks, Threats, and Vulnerabilities, each with a full explanation — no account needed. This section sits in the Security part of the exam. Answer every question to see your score, then read the lessons below for anything you missed.

220-1202
Exam
10
Questions
4
Lessons
0 / 10 answered
Q1 · 2.5

A secure area uses RFID badges for door access. Staff report that people regularly slip in behind an employee who has just badged through, before the door closes, without that employee noticing and without scanning a badge of their own. Which term describes this behavior?

Q2 · 2.5

A user at a coffee shop connects to a Wi-Fi network named 'CoffeeShopWiFi' and is immediately asked to enter their email password to 'verify access.' After submitting, the page reloads and asks again, and the browser then shows a certificate warning on a site that normally loads fine. Which type of attack is MOST likely occurring?

Q3 · 2.5

An employee receives a text message claiming to be from a shipping carrier: 'Package held due to address error. Update now: [link].' The message creates urgency and includes a shortened link. Which type of social engineering attack is this?

Q4 · 2.5

A help desk technician receives a phone call from someone claiming to be from the internal service desk. The caller says an MFA failure locked the user's account and asks the user to read back the one-time code they just received. What is the BEST response?

Q5 · 2.5

A company's public website suddenly becomes unreachable. Firewall logs show a massive volume of inbound traffic originating from thousands of different IP addresses across many geographic locations, while the server's CPU and memory usage remain normal. Which attack is MOST likely occurring?

Q6 · 2.5

While walking toward a badge-controlled server room, a technician is approached by a person carrying boxes who says, 'My badge isn't working, can you hold the door for me?' Which action BEST addresses the security risk?

Q7 · 2.5

Security researchers just announced a newly discovered vulnerability in a widely used VPN client, and there is currently no vendor fix available. Attackers are already exploiting it. Which action is the MOST appropriate immediate response for the support team?

Q8 · 2.5

An accounts payable employee receives an email that appears to come from the CEO: 'Need you to wire $48,600 to the new account for the acquisition. I'm in meetings, confirm when sent.' The message pressures for fast action and bypasses normal approval. Which type of attack is this?

Q9 · 2.5

A user reports repeated certificate warnings across multiple trusted websites, frequent session drops requiring re-authentication, and being redirected to a login page they did not request. These symptoms appeared after joining an unfamiliar network. Which attack BEST explains these combined symptoms?

Q10 · 2.5

A user notices a QR code sticker on a parking kiosk labeled 'Scan to pay.' The sticker appears to be placed over another label with peeling edges and mismatched branding. What is the BEST security practice in this situation?

Study this section

Every lesson that covers Social Engineering Attacks, Threats, and Vulnerabilities on the 220-1202 exam.

Free PBQs for this section

Interactive performance-based questions on Social Engineering Attacks, Threats, and Vulnerabilities, graded instantly.

More 220-1202 sections