SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A caller says they are from IT support and asks a user to read back the one-time MFA code that just arrived on their phone. What type of attack is this most likely?
⚠ Common exam trap
The trap here is that candidates see 'MFA code' and 'phone' and incorrectly assume smishing (SMS-based phishing), but the attack vector is the voice call, not the text message, which defines it as vishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
This is a vishing (voice phishing) attack because the attacker uses a phone call to socially engineer the victim into revealing a one-time MFA code. Unlike phishing (email) or smishing (SMS), vishing relies on voice communication to bypass technical controls and trick the user into providing the code, which the attacker can then use to authenticate as the victim.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a broad social-engineering category that typically uses email, malicious links, or fake websites to steal credentials, often through a written message rather than a live conversation. While vishing is technically a subset of phishing, the label "phishing" by itself usually implies an electronic written lure. The scenario's key characteristic is the real-time voice call guiding the user to disclose an MFA code, which makes the specific term "vishing" more accurate.
- ✗
Smishing
Why it's wrong here
Smishing is a phishing variant delivered over SMS text messages, where attackers send a fraudulent link or a prompt to reply with personal data. A text-based attack is asynchronous and lacks the immediate, interactive social-engineering pressure of a live phone call. Because the attacker is actively calling the user and verbally directing them to read a one-time code, the attack is vishing, not smishing.
- ✓
Vishing
Why this is correct
Vishing is voice phishing, where an attacker uses a phone call or VoIP call to manipulate a target. Asking for an MFA code by phone is a common and dangerous tactic because the attacker may be trying to complete a real login.
- ✗
Baiting
Why it's wrong here
Baiting relies on offering a physical or digital lure, such as a free USB drive, a gift card, or a tempting download, to persuade the user to take an action that compromises security. The attacker in this scenario does not offer a reward; instead, they pose as IT staff to create false authority and urgency. This is a pretext-based telephone scam, not a baiting attack, because the compromise comes from social manipulation rather than a planted trap or enticement.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Vishing
Vishing is a social engineering attack where criminals use phone calls or voice messages to trick victims into revealing sensitive information.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.