Courseiva
Threats, Vulnerabilities, and MitigationshardMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A facilities manager receives an SMS from "FedEx Delivery" saying a shipment for the research lab cannot clear security until the recipient verifies the package by signing in. The message includes the manager's initials and the warehouse code, and the link opens a cloned sign-in page. Which attack is most likely?

⚠ Common exam trap

Watch out — candidates often confuse the targeted nature of the message (which suggests spear phishing) with the delivery vector (SMS), but the exam specifically tests the distinction between phishing subtypes based on the communication channel used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing, because the attacker is using a text message to deliver a targeted credential lure.

Smishing is a social engineering attack that uses SMS (Short Message Service) to deliver a fraudulent message designed to trick the recipient into revealing sensitive information. In this scenario, the attacker sends a text message impersonating FedEx, includes the manager's initials and warehouse code for personalization, and provides a link to a cloned sign-in page, which is the classic credential-harvesting mechanism of a smishing attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smishing, because the attacker is using a text message to deliver a targeted credential lure.

    Why this is correct

    Smishing is the best answer because the attack arrives by SMS and is designed to push the victim to a fake login page. The personalized details make it more convincing, but the defining factor is the text-message delivery channel combined with credential harvesting. This is a common real-world approach for bypassing inbox filtering and exploiting mobile trust.

  • Vishing, because the attacker is pretending to be a delivery service representative.

    Why it's wrong here

    Vishing is incorrect because the attack vector is SMS, not a voice call. Vishing (voice phishing) relies on telephone conversations or VoIP to create urgency and socially engineer the victim, whereas this scenario uses a text message that directs the recipient to a phishing URL. Although impersonating a delivery service is a common social engineering ploy, the delivery channel determines the classification: text-message-based credential theft is smishing, not vishing.

  • Spear phishing, because the message is targeted using the recipient's role and location.

    Why it's wrong here

    Spear phishing is a broader category that refers to any targeted phishing attack customized for a specific individual or organization, often using personal details like job role or location. However, when the attack is delivered via SMS and focuses on harvesting login credentials through a mobile link, the more precise and correct term is smishing. Choosing spear phishing would ignore the primary channel that defines the attack, even though the personalization is a notable characteristic.

  • Baiting, because the message offers a shipment verification reward to encourage action.

    Why it's wrong here

    Baiting involves offering an attractive lure—such as free downloads, USB drives, or other rewards—to entice the victim into performing an action that installs malware or reveals sensitive data. In this scenario, the message does not promise a reward; it presents an urgent notification about a package delivery and asks for login credentials. The goal is direct credential theft, not the exploitation of the victim's desire for a reward, making baiting an incorrect classification.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.