Social engineering terms describe different aspects of an attack. Some name the communication channel, while others describe how carefully the victim was selected. A Security+ question becomes clearer when you separate those dimensions rather than assuming every label is mutually exclusive.
A text message with an urgent link
In an original example, a person receives a text message claiming that a parcel cannot be delivered until a small payment is made. The link leads to a page asking for card details. If the question asks for the communication-based attack type, smishing is the direct answer because the lure arrives by text message.
The urgency and payment request help explain the deception. They do not change a text message into a voice call simply because the sender impersonates a support department.
A caller who claims to be IT support
A second example involves a phone caller asking an employee to disclose an authentication code. The voice channel points to vishing. A convincing caller ID or knowledge of the employee's name does not establish that the caller is authorized.
CISA's phishing reference distinguishes these communication methods. In a real situation, the safer response is to verify through a known independent channel rather than continuing through contact details supplied by the suspicious message.
A message crafted for one organization
A third scenario describes a carefully personalized email to a specific finance employee, referring to an actual supplier relationship and asking for a bank-account change. The targeting suggests spear phishing. If a question specifically emphasizes an executive or other high-value senior target, whaling may be the more precise targeting label.
Use the CompTIA Security+ scenario practice to inspect what the question actually asks you to identify. A targeted message can also arrive through a particular channel; choosing the best option requires attention to that wording.
Turn a label into an explanation
For every scenario, write three short notes: the channel, the target, and the requested action. “Text; broad delivery lure; enter payment details” explains the first example more clearly than simply writing “scam.”
The Security+ social engineering study guide provides context for social engineering alongside identity and security controls. Add the observable clue that would help someone pause: an unexpected request, pressure to bypass a process, or a change to payment instructions.
When reviewing answer choices, reject explanations based only on spelling mistakes. A polished message can still be malicious. The better study habit is to evaluate the request and verification path, then attach the most accurate term to the evidence in the scenario.