Courseiva
Question 896 of 1,013
Threats, Vulnerabilities, and MitigationsmediumMultiple SelectObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A help desk technician receives a phone call from someone claiming to be the VP of Finance. The caller says they are in an airport, forgot their phone, and need a password reset immediately. They also ask the technician to skip callback verification because a meeting starts in five minutes. Which two details are the strongest indicators of a pretexting or vishing attempt? Select two.

⚠ Common exam trap

It's easy for candidates to confuse a successful security question response (Option D) as a sign of legitimacy, but in vishing attacks, attackers often gather personal data from OSINT or data breaches to answer such questions, making it a weak indicator compared to the direct authority pressure and request to bypass verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

the caller claims an executive title and uses authority to pressure the technician

The caller's use of an executive title (VP of Finance) and urgent authority pressure is a classic social engineering tactic known as pretexting. In a vishing (voice phishing) attack, the attacker fabricates a scenario to manipulate the technician into bypassing standard security procedures. This aligns with the SY0-701 domain on threats, vulnerabilities, and mitigations, specifically social engineering techniques.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • the caller claims an executive title and uses authority to pressure the technician

    Why this is correct

    Impersonating a senior executive is a common social engineering tactic because it creates authority pressure and makes the target more likely to comply quickly. In a help desk context, attackers often borrow a title that sounds urgent and important. That pressure is a strong sign the call may be a pretext rather than a legitimate request.

  • the call is routed through the company ticketing system with an approved change record

    Why it's wrong here

    A documented request with an approved change record would support legitimate administrative action, not social engineering. Proper workflow and traceability reduce the likelihood of a pretext. This option describes a controlled process, which is the opposite of the suspicious behavior in the scenario.

  • the caller asks the technician to bypass identity verification and callback procedures

    Why this is correct

    Requests to bypass normal verification are among the strongest red flags in any help desk interaction. Legitimate users usually expect identity checks, while attackers try to avoid them. Asking for an exception to established process is a classic attempt to weaken controls and increase the chance of unauthorized access.

  • the caller answers all security questions correctly after being prompted for them

    Why it's wrong here

    Correct answers to security questions do not automatically prove fraud, and they may simply mean the caller is a legitimate user who knows the information. The suspicious part of the scenario is the pressure to skip verification. Social engineering is indicated more by process evasion than by a user being able to answer questions.

  • the call occurs after normal business hours on a holiday weekend

    Why it's wrong here

    Unusual timing can raise suspicion, but it is not as strong as impersonation and a request to skip verification. Real support requests can occur outside normal hours. The strongest indicators are the manipulative tactics used to create urgency and bypass established identity checks.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.