SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A help desk technician receives a phone call from someone claiming to be the VP of Finance. The caller says they are in an airport, forgot their phone, and need a password reset immediately. They also ask the technician to skip callback verification because a meeting starts in five minutes. Which two details are the strongest indicators of a pretexting or vishing attempt? Select two.
⚠ Common exam trap
It's easy for candidates to confuse a successful security question response (Option D) as a sign of legitimacy, but in vishing attacks, attackers often gather personal data from OSINT or data breaches to answer such questions, making it a weak indicator compared to the direct authority pressure and request to bypass verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
the caller claims an executive title and uses authority to pressure the technician
The caller's use of an executive title (VP of Finance) and urgent authority pressure is a classic social engineering tactic known as pretexting. In a vishing (voice phishing) attack, the attacker fabricates a scenario to manipulate the technician into bypassing standard security procedures. This aligns with the SY0-701 domain on threats, vulnerabilities, and mitigations, specifically social engineering techniques.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
the caller claims an executive title and uses authority to pressure the technician
Why this is correct
Impersonating a senior executive is a common social engineering tactic because it creates authority pressure and makes the target more likely to comply quickly. In a help desk context, attackers often borrow a title that sounds urgent and important. That pressure is a strong sign the call may be a pretext rather than a legitimate request.
- ✗
the call is routed through the company ticketing system with an approved change record
Why it's wrong here
A documented request with an approved change record would support legitimate administrative action, not social engineering. Proper workflow and traceability reduce the likelihood of a pretext. This option describes a controlled process, which is the opposite of the suspicious behavior in the scenario.
- ✓
the caller asks the technician to bypass identity verification and callback procedures
Why this is correct
Requests to bypass normal verification are among the strongest red flags in any help desk interaction. Legitimate users usually expect identity checks, while attackers try to avoid them. Asking for an exception to established process is a classic attempt to weaken controls and increase the chance of unauthorized access.
- ✗
the caller answers all security questions correctly after being prompted for them
Why it's wrong here
Correct answers to security questions do not automatically prove fraud, and they may simply mean the caller is a legitimate user who knows the information. The suspicious part of the scenario is the pressure to skip verification. Social engineering is indicated more by process evasion than by a user being able to answer questions.
- ✗
the call occurs after normal business hours on a holiday weekend
Why it's wrong here
Unusual timing can raise suspicion, but it is not as strong as impersonation and a request to skip verification. Real support requests can occur outside normal hours. The strongest indicators are the manipulative tactics used to create urgency and bypass established identity checks.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.