Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A finance manager gets a phone call from someone claiming to be the CEO's assistant, urgently requesting a wire transfer before a board meeting. What type of attack is this?

⚠ Common exam trap

It's easy for candidates to confuse the delivery method (phone call) with the attack type, often choosing 'spear phishing' because the target is a specific individual, but the defining characteristic is the voice channel, not the targeting precision.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vishing

B is correct because vishing (voice phishing) uses a phone call to socially engineer the victim into performing a sensitive action, such as a wire transfer. The attacker impersonates a trusted authority (the CEO's assistant) and exploits urgency to bypass normal verification procedures. This is distinct from text-based phishing (smishing) or targeted email attacks (spear phishing).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smishing

    Why it's wrong here

    Smishing is a phishing variant delivered specifically via SMS text messages, often embedding a malicious link or a phone number that the victim is urged to contact. Since the incident described is a live voice call from the caller to the finance manager, there is no text-based payload or messaging platform involved, so this category does not apply.

  • Vishing

    Why this is correct

    Vishing, or voice phishing, is a social engineering technique that uses phone calls to impersonate a trusted entity while manufacturing urgency or fear to manipulate the victim into revealing sensitive information or performing a financial action. The finance manager's situation directly matches this pattern because the attacker uses real-time voice interaction and a claimed identity to exploit trust.

  • Spear phishing

    Why it's wrong here

    Spear phishing is a highly targeted cyberattack that typically relies on an electronic message, such as an email, crafted with personalized information about the victim to increase credibility. Even though a finance manager could be a spear-phishing target, the attack vector in this scenario is a verbal phone call rather than a written message, so the classification is incorrect.

  • Watering-hole attack

    Why it's wrong here

    A watering-hole attack involves the attacker compromising a website that the intended victims are known to visit, then planting malicious code or a redirection to deliver malware. This scenario contains no reference to a compromised web resource or to the finance manager browsing a site; the interaction is a direct phone call, making this option entirely inapplicable.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.