SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A finance clerk reports a call from a person who claimed to be from the bank's fraud department. The caller knew the employee's name, referenced a recent invoice, and asked the employee to read back a one-time MFA code to stop a supposed payment block. Which attack is most likely?
⚠ Common exam trap
Candidates often confuse the delivery method (voice vs. text) and focusing on the content (request for a code) rather than the channel, leading candidates to incorrectly choose smishing when the attack is clearly voice-based.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing, because the attacker is using a voice call to manipulate the target in real time.
The attack is vishing (voice phishing) because the attacker uses a telephone call to socially engineer the target into divulging a one-time MFA code. The real-time voice interaction and the specific request for an authentication code are hallmarks of vishing, which exploits human trust rather than technical vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Vishing, because the attacker is using a voice call to manipulate the target in real time.
Why this is correct
Vishing is voice-based phishing. The attacker used a phone call, gained trust with specific details, and pressured the employee to reveal an MFA code. That real-time conversation and the request for a secret value are classic indicators of a voice social engineering attempt.
- ✗
Smishing, because the attacker requested a code and mentioned a financial problem.
Why it's wrong here
Smishing is a form of phishing conducted via SMS text messaging, often embedding a malicious link or instructing the victim to call a number. The reported incident took place during a live phone call, making the delivery mechanism voice rather than text. The presence of a financial pretext and a request for a code does not override the channel, so the attack is correctly identified as vishing, not smishing.
- ✗
Baiting, because the caller offered to fix the payment issue for the employee.
Why it's wrong here
Baiting is a social engineering technique that entices a victim with an attractive offer, such as a free USB drive or a fake software update, to get them to perform an action that compromises security. In this case, the caller's promise to resolve a payment issue is a false pretext used during a conversation, not a tangible or digital lure left for the victim to discover and interact with. The attack relies on real-time persuasion over the phone, which is characteristic of vishing, not baiting.
- ✗
Tailgating, because the attacker used a trusted identity to gain access.
Why it's wrong here
Tailgating is a physical access control attack in which an unauthorized person slips through a secure door or gate by following an authorized employee, often exploiting a courtesy hold or unawareness. This scenario occurred entirely over a telephone, with no physical proximity, entrance, or badge-controlled checkpoint involved. Although the attacker impersonated a trusted IT representative, that is a social engineering tactic common to vishing, not the physical follow-behind method that defines tailgating.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Vishing
Vishing is a social engineering attack where criminals use phone calls or voice messages to trick victims into revealing sensitive information.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
5 more ways this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A finance manager gets a phone call from someone claiming to be the CEO's assistant, urgently requesting a wire transfer before a board meeting. What type of attack is this?
easy- A.Smishing
- ✓ B.Vishing
- C.Spear phishing
- D.Watering-hole attack
Why B: B is correct because vishing (voice phishing) uses a phone call to socially engineer the victim into performing a sensitive action, such as a wire transfer. The attacker impersonates a trusted authority (the CEO's assistant) and exploits urgency to bypass normal verification procedures. This is distinct from text-based phishing (smishing) or targeted email attacks (spear phishing).
Variation 2. A user receives a phone call from someone who claims to be a member of the company's IT support team. The caller states that the user's account has been compromised and requests the user's username, password, and the current multi-factor authentication (MFA) code to 'verify identity and secure the account.' Which type of social engineering attack is being attempted?
medium- A.Spear phishing
- ✓ B.Vishing
- C.Pretexting
- D.Tailgating
Why B: B is correct because vishing (voice phishing) is a social engineering attack conducted over the phone, where the attacker impersonates a trusted entity (IT support) to trick the victim into revealing sensitive information such as credentials and MFA codes. The request for the current MFA code is a key indicator, as it would allow the attacker to bypass multi-factor authentication in real time.
Variation 3. A help desk technician receives a phone call from someone who claims to be the CFO. The caller says they are traveling, cannot access their MFA app, and needs the technician to reset the account immediately. They also ask the technician to read back the one-time code sent to the executive's phone so they can "verify identity." What type of attack is this most likely?
medium- A.Pretexting
- ✓ B.Vishing
- C.Smishing
- D.Baiting
Why B: This is vishing (voice phishing) because the attacker uses a phone call to impersonate a trusted executive (the CFO) and manipulates the technician into bypassing MFA controls. The request to read back the one-time code is a classic social engineering tactic to capture a valid OTP, which the attacker can then use to authenticate as the CFO.
Variation 4. A help desk technician receives a phone call from someone claiming to be a contractor. The caller says their MFA app was lost, asks the technician to enroll a new device immediately, and pressures them to ignore policy. What type of attack is this?
easy- A.Phishing
- ✓ B.Vishing
- C.Smishing
- D.Baiting
Why B: This is a vishing (voice phishing) attack because the attacker uses a phone call to impersonate a contractor and socially engineer the technician into bypassing MFA enrollment policies. Vishing specifically exploits voice communication to manipulate victims, unlike phishing which uses email or malicious links.
Variation 5. A help desk technician reviews a voicemail in which the caller claims to be from the security team, says the user will be locked out unless they read back a one-time passcode, and leaves a callback number. What type of attack is this?
medium- A.Smishing, because the attacker is using a text message with a link.
- ✓ B.Vishing, because the attacker is using voice communication to pressure the user.
- C.Baiting, because the attacker is offering a reward to entice the user.
- D.Pretexting, because the attacker invented a role and story.
Why B: Vishing (voice phishing) uses voice communication—such as phone calls or voicemails—to trick victims into revealing sensitive information. In this scenario, the attacker leaves a voicemail claiming to be from the security team and pressures the user to read back a one-time passcode, which is a classic vishing tactic that exploits trust and urgency over voice channels.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.