SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A caller claims to be from the company's SaaS provider and says a tenant migration will fail unless the help desk reads back a one-time verification code sent to an administrator's phone. The caller knows the admin's name and ticket number. What attack technique is being used?
⚠ Common exam trap
Candidates often confuse pretexting with whaling because both involve impersonation, but whaling targets high-level executives directly, while pretexting uses a fabricated scenario to trick any employee into performing an action or revealing information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting, because the attacker is inventing a believable support story to gain trust.
The attacker is using pretexting by fabricating a plausible scenario (a tenant migration requiring a verification code) to manipulate the help desk into divulging sensitive information. This social engineering technique relies on building false trust through invented details like the admin's name and ticket number, rather than exploiting technical vulnerabilities. The goal is to obtain the one-time verification code, which could be used for unauthorized access or account takeover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Pretexting, because the attacker is inventing a believable support story to gain trust.
Why this is correct
The attacker is using a fabricated identity and a credible business scenario to manipulate the help desk into revealing a verification code. That is classic pretexting. The known name and ticket number are used to increase legitimacy, but the key behavior is the false story intended to bypass normal trust checks.
- ✗
Watering hole, because the attacker is targeting a trusted web service used by employees.
Why it's wrong here
A watering hole attack requires the attacker to compromise a legitimate website that the target population routinely visits, then inject malware or a malicious script to infect their browsers or devices. In this phone call, there is no compromised web resource, no malware payload, and no automated exploit; the delivery channel is direct social engineering over a live call. Thus, while the call may reference a trusted service, that does not make it a watering hole attack.
- ✗
Tailgating, because the attacker is attempting to bypass a physical security barrier.
Why it's wrong here
Tailgating is a physical security bypass in which an unauthorized person follows closely behind an authorized employee through a door, gate, or other controlled access point, often exploiting the employee's courtesy or inattention. Here, the attacker never physically approaches a facility, presents a badge, or passes through a controlled barrier. The entire interaction is telephonic and aims to extract a verification code, so categorizing this as tailgating conflates a physical access technique with an information-gathering pretext.
- ✗
Whaling, because the attacker is targeting a high-value executive account directly.
Why it's wrong here
Whaling is a precision phishing attack directed at senior executives, such as CEOs or CFOs, typically through email or messaging and aimed at stealing credentials, initiating fraudulent wire transfers, or compromising executive accounts. In this scenario, the attacker calls a help desk and impersonates a SaaS provider, not a C-suite leader, and the target is a support agent with access to verification codes, not an executive's inbox. The recognized names and ticket numbers are part of a pretexting ruse, not a whaling campaign.
Go deeper
Related to this question
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.