Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A help desk analyst receives a ticket stating that an employee got an urgent text message from someone claiming to be the CEO. The message asked the employee to buy gift cards and send the redemption codes immediately. What attack is most likely taking place?

⚠ Common exam trap

Watch out — candidates often confuse smishing with general phishing (Option A) because both involve deceptive messages, but the exam specifically tests the delivery vector—SMS vs. email—as the key differentiator for attack classification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing, because the attacker is using SMS or text messaging to trick the employee into taking an action.

The attack uses SMS/text messaging as the delivery vector, which is the defining characteristic of smishing. The urgent request to buy gift cards and send redemption codes is a classic social engineering tactic designed to exploit the employee's trust in the CEO's authority, not to steal credentials or install malware directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing, because the attacker is trying to steal information through a deceptive message sent to a user.

    Why it's wrong here

    Phishing is a broad umbrella term for social engineering that relies on deceptive messages, but the specific delivery medium here—SMS or text message—distinguishes this as smishing. While the attacker's goal of stealing gift card codes does fit phishing's definition, the industry-standard terminology for text-message-based attacks is smishing, not generic phishing. Choosing 'phishing' overlooks the channel-specific attack vector and is therefore less technically precise than 'smishing.'

  • Smishing, because the attacker is using SMS or text messaging to trick the employee into taking an action.

    Why this is correct

    Smishing is phishing delivered through text messaging. The attacker is impersonating an executive and creating urgency to pressure the employee into buying gift cards and revealing codes. That combination of mobile delivery, impersonation, and urgency fits a text-based social engineering attack.

  • Vishing, because the attacker is using a phone call to pressure the employee into complying.

    Why it's wrong here

    Vishing, or voice phishing, specifically depends on a real-time telephone call, VoIP call, or voicemail message to exploit the target's trust through spoken interaction. The scenario describes an SMS or text-based message delivered to a mobile device, not a phone call; therefore, the attack vector does not match vishing. Even if the attacker impersonates an executive and creates urgency, those social-engineering tactics are not exclusive to vishing and do not change the text-based delivery channel.

  • Baiting, because the attacker is tempting the user with a reward in exchange for cooperation.

    Why it's wrong here

    Baiting typically employs a physical or digital lure—such as a poisoned USB drive, a free download, or a promise of a reward—to entice a victim into performing an action that compromises security. In this scenario, the attacker exploits authority and urgency by impersonating an executive and demanding gift-card purchases, rather than offering any tempting reward or incentive. Since no 'bait' or promised benefit is dangled in front of the employee, labeling this as baiting misidentifies the core manipulation technique.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.