SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A help desk analyst receives a ticket stating that an employee got an urgent text message from someone claiming to be the CEO. The message asked the employee to buy gift cards and send the redemption codes immediately. What attack is most likely taking place?
⚠ Common exam trap
Watch out — candidates often confuse smishing with general phishing (Option A) because both involve deceptive messages, but the exam specifically tests the delivery vector—SMS vs. email—as the key differentiator for attack classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing, because the attacker is using SMS or text messaging to trick the employee into taking an action.
The attack uses SMS/text messaging as the delivery vector, which is the defining characteristic of smishing. The urgent request to buy gift cards and send redemption codes is a classic social engineering tactic designed to exploit the employee's trust in the CEO's authority, not to steal credentials or install malware directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing, because the attacker is trying to steal information through a deceptive message sent to a user.
Why it's wrong here
Phishing is a broad umbrella term for social engineering that relies on deceptive messages, but the specific delivery medium here—SMS or text message—distinguishes this as smishing. While the attacker's goal of stealing gift card codes does fit phishing's definition, the industry-standard terminology for text-message-based attacks is smishing, not generic phishing. Choosing 'phishing' overlooks the channel-specific attack vector and is therefore less technically precise than 'smishing.'
- ✓
Smishing, because the attacker is using SMS or text messaging to trick the employee into taking an action.
Why this is correct
Smishing is phishing delivered through text messaging. The attacker is impersonating an executive and creating urgency to pressure the employee into buying gift cards and revealing codes. That combination of mobile delivery, impersonation, and urgency fits a text-based social engineering attack.
- ✗
Vishing, because the attacker is using a phone call to pressure the employee into complying.
Why it's wrong here
Vishing, or voice phishing, specifically depends on a real-time telephone call, VoIP call, or voicemail message to exploit the target's trust through spoken interaction. The scenario describes an SMS or text-based message delivered to a mobile device, not a phone call; therefore, the attack vector does not match vishing. Even if the attacker impersonates an executive and creates urgency, those social-engineering tactics are not exclusive to vishing and do not change the text-based delivery channel.
- ✗
Baiting, because the attacker is tempting the user with a reward in exchange for cooperation.
Why it's wrong here
Baiting typically employs a physical or digital lure—such as a poisoned USB drive, a free download, or a promise of a reward—to entice a victim into performing an action that compromises security. In this scenario, the attacker exploits authority and urgency by impersonating an executive and demanding gift-card purchases, rather than offering any tempting reward or incentive. Since no 'bait' or promised benefit is dangled in front of the employee, labeling this as baiting misidentifies the core manipulation technique.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Exploit
An exploit is a piece of code, a sequence of commands, or a technique that takes advantage of a vulnerability in a system or software to cause unintended behavior, often for malicious purposes.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.