SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A help desk technician receives a phone call from someone who claims to be the CFO. The caller knows the executive team structure, says they are traveling, and insists the technician reset MFA to 'avoid delaying a wire transfer.' Which social engineering technique is the caller primarily using?
⚠ Common exam trap
Test-takers frequently confuse the delivery method (voice call = vishing) with the underlying social engineering technique (pretexting), but the question specifically asks for the primary technique being used, not the channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting, because the caller builds a believable story to manipulate the employee
The caller is using pretexting because they have fabricated a scenario (the CFO traveling and needing an urgent wire transfer) and assumed a false identity to manipulate the help desk technician into resetting MFA. Pretexting relies on a crafted story or pretext to gain trust and bypass security controls, which is exactly what the caller is doing here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Pretexting, because the caller builds a believable story to manipulate the employee
Why this is correct
Pretexting is the best fit because the attacker invents a convincing scenario, uses insider details, and pressures the technician to bypass normal verification. The goal is not just to trick someone into clicking a link, but to create a false identity and narrative that makes the request seem legitimate. This is a common tactic in help desk fraud and account takeover attempts.
- ✗
Baiting, because the caller is offering something valuable in exchange for action
Why it's wrong here
Baiting is a social engineering technique that dangles an enticing object, download, or promise—like free media, a gift card, or a lost USB drive—to induce a victim into performing an action that compromises security. In this scenario, the caller offers no tangible reward; instead, they fabricate a believable identity and narrative to convince the technician to reset a password or grant access. The attack's core mechanism is a pretext for trust, not an irresistible offer, so it does not match baiting.
- ✗
Vishing, because the attack happens by voice call
Why it's wrong here
Vishing (voice phishing) is a delivery channel where attackers use phone calls to elicit sensitive information, often by spoofing caller ID to impersonate a bank or IT department. While this incident does occur over a call, vishing typically relies on generic urgency as the primary persuasive hook, such as 'your account is compromised, verify your SSN.' The technician here is manipulated by a detailed, false biography and procedural circumvention—hallmarks of pretexting, not the medium-specific phishing style. Thus, classifying it as vishing misidentifies the psychological tactic in favor of the transmission method.
- ✗
Smishing, because the attacker is using a mobile device
Why it's wrong here
Smishing is phishing conducted via SMS/text messaging, where a user receives a link to a fake login page or malware-laden download in a message. The scenario explicitly describes a real-time voice conversation, not a text exchange, so smishing cannot be the correct classification. Moreover, the attacker's effectiveness stems from pretexting—building a convincing backstory—rather than from any exploit of mobile messaging protocols. Therefore, smishing is wrong because it confuses the simple use of a telephone with a distinct, SMS-based attack vector.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Pretexting
Pretexting is a social engineering attack where the attacker fabricates a believable scenario or false identity to trick a victim into revealing sensitive information or performing an action.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A caller claims to be from the company's SaaS provider and says a tenant migration will fail unless the help desk reads back a one-time verification code sent to an administrator's phone. The caller knows the admin's name and ticket number. What attack technique is being used?
medium- ✓ A.Pretexting, because the attacker is inventing a believable support story to gain trust.
- B.Watering hole, because the attacker is targeting a trusted web service used by employees.
- C.Tailgating, because the attacker is attempting to bypass a physical security barrier.
- D.Whaling, because the attacker is targeting a high-value executive account directly.
Why A: The attacker is using pretexting by fabricating a plausible scenario (a tenant migration requiring a verification code) to manipulate the help desk into divulging sensitive information. This social engineering technique relies on building false trust through invented details like the admin's name and ticket number, rather than exploiting technical vulnerabilities. The goal is to obtain the one-time verification code, which could be used for unauthorized access or account takeover.
Variation 2. A caller says they are from the help desk and need the employee's MFA code to "complete a password reset". Which social engineering technique is being used?
easy- A.Phishing
- ✓ B.Pretexting
- C.DDoS
- D.SQL injection
Why B: Pretexting is a social engineering technique where an attacker fabricates a scenario (the pretext) to trick a victim into divulging sensitive information. In this case, the attacker pretends to be from the help desk and invokes a false password reset procedure to obtain the employee's MFA code, which should never be shared. The MFA code is a time-based one-time password (TOTP) or push notification response that authenticates the user, not a tool for password resets.
Variation 3. A help desk technician receives a phone call from someone claiming to be the VP of Finance. The caller says they are in an airport, forgot their phone, and need a password reset immediately. They also ask the technician to skip callback verification because a meeting starts in five minutes. Which two details are the strongest indicators of a pretexting or vishing attempt? Select two.
medium- ✓ A.the caller claims an executive title and uses authority to pressure the technician
- B.the call is routed through the company ticketing system with an approved change record
- ✓ C.the caller asks the technician to bypass identity verification and callback procedures
- D.the caller answers all security questions correctly after being prompted for them
- E.the call occurs after normal business hours on a holiday weekend
Why A: The caller's use of an executive title (VP of Finance) and urgent authority pressure is a classic social engineering tactic known as pretexting. In a vishing (voice phishing) attack, the attacker fabricates a scenario to manipulate the technician into bypassing standard security procedures. This aligns with the SY0-701 domain on threats, vulnerabilities, and mitigations, specifically social engineering techniques.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.