Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A help desk technician receives a phone call from someone who claims to be the CFO. The caller knows the executive team structure, says they are traveling, and insists the technician reset MFA to 'avoid delaying a wire transfer.' Which social engineering technique is the caller primarily using?

⚠ Common exam trap

Test-takers frequently confuse the delivery method (voice call = vishing) with the underlying social engineering technique (pretexting), but the question specifically asks for the primary technique being used, not the channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Pretexting, because the caller builds a believable story to manipulate the employee

The caller is using pretexting because they have fabricated a scenario (the CFO traveling and needing an urgent wire transfer) and assumed a false identity to manipulate the help desk technician into resetting MFA. Pretexting relies on a crafted story or pretext to gain trust and bypass security controls, which is exactly what the caller is doing here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pretexting, because the caller builds a believable story to manipulate the employee

    Why this is correct

    Pretexting is the best fit because the attacker invents a convincing scenario, uses insider details, and pressures the technician to bypass normal verification. The goal is not just to trick someone into clicking a link, but to create a false identity and narrative that makes the request seem legitimate. This is a common tactic in help desk fraud and account takeover attempts.

  • Baiting, because the caller is offering something valuable in exchange for action

    Why it's wrong here

    Baiting is a social engineering technique that dangles an enticing object, download, or promise—like free media, a gift card, or a lost USB drive—to induce a victim into performing an action that compromises security. In this scenario, the caller offers no tangible reward; instead, they fabricate a believable identity and narrative to convince the technician to reset a password or grant access. The attack's core mechanism is a pretext for trust, not an irresistible offer, so it does not match baiting.

  • Vishing, because the attack happens by voice call

    Why it's wrong here

    Vishing (voice phishing) is a delivery channel where attackers use phone calls to elicit sensitive information, often by spoofing caller ID to impersonate a bank or IT department. While this incident does occur over a call, vishing typically relies on generic urgency as the primary persuasive hook, such as 'your account is compromised, verify your SSN.' The technician here is manipulated by a detailed, false biography and procedural circumvention—hallmarks of pretexting, not the medium-specific phishing style. Thus, classifying it as vishing misidentifies the psychological tactic in favor of the transmission method.

  • Smishing, because the attacker is using a mobile device

    Why it's wrong here

    Smishing is phishing conducted via SMS/text messaging, where a user receives a link to a fake login page or malware-laden download in a message. The scenario explicitly describes a real-time voice conversation, not a text exchange, so smishing cannot be the correct classification. Moreover, the attacker's effectiveness stems from pretexting—building a convincing backstory—rather than from any exploit of mobile messaging protocols. Therefore, smishing is wrong because it confuses the simple use of a telephone with a distinct, SMS-based attack vector.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A caller claims to be from the company's SaaS provider and says a tenant migration will fail unless the help desk reads back a one-time verification code sent to an administrator's phone. The caller knows the admin's name and ticket number. What attack technique is being used?

medium
  • A.Pretexting, because the attacker is inventing a believable support story to gain trust.
  • B.Watering hole, because the attacker is targeting a trusted web service used by employees.
  • C.Tailgating, because the attacker is attempting to bypass a physical security barrier.
  • D.Whaling, because the attacker is targeting a high-value executive account directly.

Why A: The attacker is using pretexting by fabricating a plausible scenario (a tenant migration requiring a verification code) to manipulate the help desk into divulging sensitive information. This social engineering technique relies on building false trust through invented details like the admin's name and ticket number, rather than exploiting technical vulnerabilities. The goal is to obtain the one-time verification code, which could be used for unauthorized access or account takeover.

Variation 2. A caller says they are from the help desk and need the employee's MFA code to "complete a password reset". Which social engineering technique is being used?

easy
  • A.Phishing
  • B.Pretexting
  • C.DDoS
  • D.SQL injection

Why B: Pretexting is a social engineering technique where an attacker fabricates a scenario (the pretext) to trick a victim into divulging sensitive information. In this case, the attacker pretends to be from the help desk and invokes a false password reset procedure to obtain the employee's MFA code, which should never be shared. The MFA code is a time-based one-time password (TOTP) or push notification response that authenticates the user, not a tool for password resets.

Variation 3. A help desk technician receives a phone call from someone claiming to be the VP of Finance. The caller says they are in an airport, forgot their phone, and need a password reset immediately. They also ask the technician to skip callback verification because a meeting starts in five minutes. Which two details are the strongest indicators of a pretexting or vishing attempt? Select two.

medium
  • A.the caller claims an executive title and uses authority to pressure the technician
  • B.the call is routed through the company ticketing system with an approved change record
  • C.the caller asks the technician to bypass identity verification and callback procedures
  • D.the caller answers all security questions correctly after being prompted for them
  • E.the call occurs after normal business hours on a holiday weekend

Why A: The caller's use of an executive title (VP of Finance) and urgent authority pressure is a classic social engineering tactic known as pretexting. In a vishing (voice phishing) attack, the attacker fabricates a scenario to manipulate the technician into bypassing standard security procedures. This aligns with the SY0-701 domain on threats, vulnerabilities, and mitigations, specifically social engineering techniques.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.