Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A help desk technician receives a phone call from someone claiming to be a contractor. The caller says their MFA app was lost, asks the technician to enroll a new device immediately, and pressures them to ignore policy. What type of attack is this?

⚠ Common exam trap

Many exam-takers confuse vishing with phishing because both involve social engineering, but the key differentiator is the communication medium—voice (phone call) vs. electronic message (email/SMS).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vishing

This is a vishing (voice phishing) attack because the attacker uses a phone call to impersonate a contractor and socially engineer the technician into bypassing MFA enrollment policies. Vishing specifically exploits voice communication to manipulate victims, unlike phishing which uses email or malicious links.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing is a broad social engineering technique typically delivered via email or fraudulent websites, using bulk messages that impersonate trusted entities to steal credentials or trick users into installing malware. It relies on written content and clicks rather than an interactive voice conversation. Because the reported contact is a live phone call, this scenario does not match phishing's primary delivery mechanism.

  • Vishing

    Why this is correct

    Vishing, or voice phishing, leverages live or automated phone calls, often using VoIP and caller ID spoofing to appear as a legitimate bank, IT support, or government agency. Vishing uses voice calls to pressure a target into revealing information or changing security settings, such as resetting a password or approving a multi-factor authentication prompt. The direct phone-to-phone interaction makes this the correct classification for the described call.

  • Smishing

    Why it's wrong here

    Smishing (SMS phishing) arrives as a text message, usually containing a short link or prompt to reply with personal information, and often targets mobile users by exploiting SMS trust. Unlike a phone call, smishing does not require real-time conversation and relies on the victim clicking a link or sending a text response. Since the technician received a phone call, the active voice channel rules out smishing as the correct category.

  • Baiting

    Why it's wrong here

    Baiting is a physical or digital lure attack that offers something attractive—such as free USB drives, software downloads, or 'abandoned' media—to entice victims into inserting infected devices or executing malicious files. It relies on curiosity or greed rather than a direct interpersonal phone conversation, and often occurs in person or via a downloadable trap. A phone call requesting data is not consistent with baiting, which does not use voice calls as its primary vector.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.