SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A finance manager gets a phone call from someone claiming to be the CEO's assistant, urgently requesting a wire transfer before a board meeting. What type of attack is this?
⚠ Common exam trap
It's easy for candidates to confuse the delivery method (phone call) with the attack type, often choosing 'spear phishing' because the target is a specific individual, but the defining characteristic is the voice channel, not the targeting precision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
B is correct because vishing (voice phishing) uses a phone call to socially engineer the victim into performing a sensitive action, such as a wire transfer. The attacker impersonates a trusted authority (the CEO's assistant) and exploits urgency to bypass normal verification procedures. This is distinct from text-based phishing (smishing) or targeted email attacks (spear phishing).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smishing
Why it's wrong here
Smishing is a phishing variant delivered specifically via SMS text messages, often embedding a malicious link or a phone number that the victim is urged to contact. Since the incident described is a live voice call from the caller to the finance manager, there is no text-based payload or messaging platform involved, so this category does not apply.
- ✓
Vishing
Why this is correct
Vishing, or voice phishing, is a social engineering technique that uses phone calls to impersonate a trusted entity while manufacturing urgency or fear to manipulate the victim into revealing sensitive information or performing a financial action. The finance manager's situation directly matches this pattern because the attacker uses real-time voice interaction and a claimed identity to exploit trust.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a highly targeted cyberattack that typically relies on an electronic message, such as an email, crafted with personalized information about the victim to increase credibility. Even though a finance manager could be a spear-phishing target, the attack vector in this scenario is a verbal phone call rather than a written message, so the classification is incorrect.
- ✗
Watering-hole attack
Why it's wrong here
A watering-hole attack involves the attacker compromising a website that the intended victims are known to visit, then planting malicious code or a redirection to deliver malware. This scenario contains no reference to a compromised web resource or to the finance manager browsing a site; the interaction is a direct phone call, making this option entirely inapplicable.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Vishing
Vishing is a social engineering attack where criminals use phone calls or voice messages to trick victims into revealing sensitive information.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.