ArticleCompTIA Security+ SY0-701Updated 6/10/20267 min read

Phishing, Smishing, and Vishing: Match the Attack Channel

These terms are mostly about the delivery channel: phishing is commonly email, smishing is SMS/text, and vishing is voice.

Plain answer firstScenario cuesTerm comparisonQuick practice questions

Quick answer

Phishing uses deceptive messages, commonly email, to trick users. Smishing is phishing through SMS or text messages. Vishing uses voice calls or voicemail. The exam cue is usually the communication channel and the manipulation tactic.

Start with the channel

A fake password reset email is phishing. A fake delivery text is smishing. A phone call pretending to be the bank is vishing.

Security+ questions may add urgency, impersonation, links, attachments, or credential theft. Those are manipulation cues, but the term often depends on the channel.

The related control answer may involve user awareness, reporting, email filtering, MFA, or verification procedures.

  • Phishing: deceptive message, commonly email.
  • Smishing: SMS/text-message phishing.
  • Vishing: voice-based social engineering.
  • Spear phishing: targeted phishing against a specific person or group.

Social engineering terms compared

Phishing

Best for

Broad deceptive messages, often email.

Exam cue

Email link, fake login page, attachment, urgent message.

Common mistake

Using it when the scenario specifically says SMS or voice.

Smishing

Best for

Text-message scams.

Exam cue

SMS, text, mobile message, delivery notice link.

Common mistake

Calling it generic phishing when smishing is an option.

Vishing

Best for

Voice-call scams.

Exam cue

Phone call, voicemail, caller impersonation.

Common mistake

Choosing phishing because credentials are requested.

Spear phishing

Best for

Targeted phishing.

Exam cue

Personalized attack against an executive, admin, or specific team.

Common mistake

Missing the targeted nature of the message.

Scenario cues to look for

A user receives a text message claiming a package failed delivery and asking them to click a link.

Answer: Smishing

The attack is delivered through SMS/text.

Why not the distractor: It is not vishing because no voice call is involved.

A caller pretends to be IT and asks for a one-time passcode.

Answer: Vishing

The voice-call channel is the strongest cue.

Why not the distractor: Credential theft can happen through many channels, but the call makes it vishing.

An email to the CFO references a current acquisition and links to a fake login page.

Answer: Spear phishing

The email is targeted and personalized.

Why not the distractor: It is more specific than broad phishing.

Common exam mistakes

1

Choosing based only on the goal of stealing credentials.

Use the channel and targeting cues to pick the exact term.

2

Ignoring urgency and impersonation.

Urgency and authority are social engineering clues even when the channel differs.

3

Forgetting verification procedures.

A secure response often means verify through a trusted separate channel.

Quick practice questions

Answer each question to reveal the explanation. The full app adds tracked results and weak-area review.

Q1.A malicious text message asks a user to click a fake delivery link. What is this called?

Q2.A scammer calls a help desk pretending to be an executive. Which term best fits?

Q3.An email is crafted specifically for one administrator using personal details. Which term is most precise?

Ready to test your knowledge?

Try the free CompTIA Security+ practice test, or use the app for tracked weak-area review.