Courseiva
Threats, Vulnerabilities, and MitigationshardMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A help desk technician receives a call from someone claiming to be a new contractor whose MFA app failed during travel. The caller knows the company org chart, names the technician's supervisor, and says the technician should use a callback number included in a text message they just sent. What is the safest first action?

⚠ Common exam trap

Many exam-takers assume the caller's knowledge of internal details (supervisor name, org chart) is sufficient proof of identity, but CompTIA tests the principle that any unsolicited request for privileged actions must be independently verified through a trusted channel, not through information the caller provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

End the call and verify the request through a published help desk number or ticketing system.

The safest first action when receiving an unsolicited call requesting privileged actions (like MFA reset) is to independently verify the request through official channels. The caller's knowledge of internal details (org chart, supervisor name) and the request to use a callback number from a text message are classic social engineering red flags, as the callback number could be attacker-controlled. Hanging up and calling back via a published help desk number ensures the request is legitimate and prevents MFA bypass or account takeover.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reset MFA immediately, since the caller has provided enough internal details to seem credible.

    Why it's wrong here

    Resetting MFA solely because the caller recites internal details is dangerous; those details are low-assurance attributes that can be harvested from social media, phishing, or prior breaches. A legitimate help desk process must first establish identity using independent, out-of-band verification (e.g., calling back a phone number from HR records) before touching MFA, otherwise the technician may be unknowingly helping an attacker enroll a new authenticator and lock out the real user.

  • Ask the caller to read a one-time code aloud so the technician can confirm their identity.

    Why it's wrong here

    Asking a caller to read a one-time code aloud transforms the technician into a tool for credential theft; OTPs are possession-based authentication factors that must only be entered into the legitimate authentication interface. If the attacker is the one receiving the code, they can replay it to complete a password reset or session takeover, so the request itself contradicts secure verification.

  • End the call and verify the request through a published help desk number or ticketing system.

    Why this is correct

    The safest first action is to stop using information supplied by the caller and verify through a trusted, independently obtained contact path. Because the attacker already knows internal details and provided a callback number in a text, those channels cannot be trusted. Using a published help desk number or the official ticketing system preserves least risk and prevents social engineering from extending into account reset abuse.

  • Approve the request if the caller can name the supervisor and the contractor's project team.

    Why it's wrong here

    Naming a supervisor and project team is a classic knowledge-based-authentication (KBA) check that fails under pretexting; an attacker can obtain such organizational details through LinkedIn, company announcements, or data brokers. Secure identity proofing requires factors beyond shared secrets, such as verifying through a known phone number or ticketing system, so this approval criterion is not an acceptable control.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.