SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A caller says they are from the help desk and need the employee's MFA code to "complete a password reset". Which social engineering technique is being used?
⚠ Common exam trap
Many candidates confuse pretexting with phishing because both involve deception, but pretexting relies on a fabricated identity and scenario (often via phone or in-person) rather than a malicious electronic message.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is a social engineering technique where an attacker fabricates a scenario (the pretext) to trick a victim into divulging sensitive information. In this case, the attacker pretends to be from the help desk and invokes a false password reset procedure to obtain the employee's MFA code, which should never be shared. The MFA code is a time-based one-time password (TOTP) or push notification response that authenticates the user, not a tool for password resets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing generally involves sending fraudulent emails or web links that direct victims to spoofed login pages, malware, or other technical payloads. The caller in this scenario is not directing the employee to a malicious link or attachment; the attacker is simply playing a convincing role (help desk) to talk the victim into revealing the code, which is the hallmark of a pretexting attack rather than phishing.
- ✓
Pretexting
Why this is correct
Pretexting is a social engineering technique in which the attacker creates an invented, believable scenario and impersonates an authority figure to lower the victim's defenses. Here, the caller's fabricated 'help desk' identity is the pretext that creates urgency and legitimacy, tricking the employee into disclosing a secret code that should never be shared over an unsolicited call.
- ✗
DDoS
Why it's wrong here
A DDoS attack uses a botnet to saturate a network or server with more requests than it can handle, causing service outages. It is a purely technical, resource-exhaustion attack with no conversational or impersonation element, so it cannot explain a caller who is using a fabricated identity to extract an employee's secret code.
- ✗
SQL injection
Why it's wrong here
SQL injection is a web application vulnerability where unsolicited database commands are inserted through input fields to alter or exfiltrate data. The described incident is a human-to-human phone conversation, not an application request, and the attacker is extracting a code through social engineering rather than manipulating a backend query.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Pretexting
Pretexting is a social engineering attack where the attacker fabricates a believable scenario or false identity to trick a victim into revealing sensitive information or performing an action.
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.