SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A help desk analyst receives a phone call from someone claiming to be the CFO, who says their phone was lost while traveling and requests an immediate MFA reset and temporary bypass for payroll access. The caller knows the CFO's last name and the company name, but cannot answer the callback verification question. What attack technique is most likely being used?
⚠ Common exam trap
Many candidates confuse vishing with phishing because both involve social engineering, but vishing is specifically voice-based, and the question's context of a phone call and callback verification failure directly points to vishing, not email-based phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
The caller is using voice communication to impersonate a high-level executive (CFO) and manipulate the help desk analyst into bypassing security controls, which is the defining characteristic of vishing (voice phishing). The request for an MFA reset and temporary bypass is a social engineering tactic to exploit the analyst's authority bias and urgency, and the inability to pass callback verification confirms the caller is not legitimate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a form of social engineering that typically uses electronic text-based media, such as email or SMS, to trick the target into clicking a malicious link, opening an attachment, or revealing credentials. In this scenario, the attacker is using a direct voice phone call, which classifies the attack under vishing (voice phishing) rather than conventional phishing. There are no lures, links, or written messages involved here, so labeling it simply as phishing doesn't accurately capture the voice-based mechanism the attacker employed.
- ✓
Vishing
Why this is correct
Vishing (voice phishing) is the correct classification because the entire attack is executed over a direct phone call, a hallmark of voice-based social engineering. The attacker creates a false sense of urgency and asserts authority, likely impersonating an executive or IT administrator, to pressure the help desk analyst into bypassing standard verification and changing authentication controls. This call is a deliberate manipulation of a human process, not a technical exploit, and vishing is specifically designed to target help desk personnel who have the power to reset credentials or alter account access.
- ✗
Baiting
Why it's wrong here
Baiting is a social engineering technique that relies on an attractive or enticing lure, such as leaving a USB drive in a parking lot or offering a fake free download, to trick the victim into physically or digitally taking a specific action. In this scenario, there is no physical or virtual bait being offered; the attacker is making a direct, urgent request over the phone. The success of the attack depends entirely on the analyst's decision to comply with the caller's demands, not on the victim being tempted by a prop. Therefore, baiting does not match the voice-call social engineering pattern observed here.
- ✗
Watering hole attack
Why it's wrong here
A watering hole attack is a cyberattack in which the attacker compromises a website that is frequently visited by the target group, injecting malicious scripts to infect users' devices when they browse the site. This is a passive attack vector that relies on the victim voluntarily visiting the compromised site, and it typically delivers malware rather than directly interacting with a person. The help desk analyst in this scenario is openly contacted by phone, with the attacker actively impersonating an insider to achieve an immediate administrative action. Since there is no website compromise or malware delivery involved, this is not a watering hole attack.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Vishing
Vishing is a social engineering attack where criminals use phone calls or voice messages to trick victims into revealing sensitive information.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.