FC0-U71 Security Practice Question
An employee at a marketing agency connects a personal smartphone to the corporate guest Wi-Fi to check social media. The phone has no screen lock and runs an outdated operating system. The IT administrator is concerned this device could serve as an entry point into the corporate network. Which term BEST describes the risk introduced by this device?
⚠ Common exam trap
The trap here is focusing on the phone's outdated software and calling it a zero-day or exploit, when the defining issue is that the device was brought onto the network without IT approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shadow IT
The scenario centers on a device IT never approved, configured, or can manage, which is the definition of shadow IT. Because the phone lacks a screen lock and current patches, it can be compromised and then used to reach corporate resources. Zero-day, privilege escalation, and social engineering describe different attack mechanics that are not present here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Social engineering
Why it's wrong here
Social engineering manipulates people into divulging information or performing actions, such as a phishing call. Here no one is being tricked into an action; the concern is an unapproved and unprotected device connecting to corporate resources, which is a policy and visibility problem rather than a human-manipulation attack.
- ✗
Privilege escalation
Why it's wrong here
Privilege escalation occurs when an attacker gains higher rights than authorized, such as moving from a standard user to administrator. The scenario describes an unmanaged device on the network, not an attacker elevating permissions on a system, so this term does not describe the entry-point risk the administrator is worried about.
- ✓
Shadow IT
Why this is correct
Shadow IT refers to technology hardware or software used inside an organization without the IT department's knowledge or approval. The personal phone joining the corporate network for non-work purposes, unmanaged and unpatched, is a classic example because IT never sanctioned or configured the device, creating unmonitored risk on the network.
- ✗
Zero-day exploit
Why it's wrong here
A zero-day is an attack that leverages a previously unknown software vulnerability before a patch exists. Nothing in the scenario indicates an unknown flaw being actively exploited; the phone simply runs an outdated but known-vulnerable operating system, so labeling this a zero-day mischaracterizes the nature of the risk.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.