SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A help desk technician receives a phone call from someone who claims to be the CFO. The caller says they are traveling, cannot access their MFA app, and needs the technician to reset the account immediately. They also ask the technician to read back the one-time code sent to the executive's phone so they can "verify identity." What type of attack is this most likely?
⚠ Common exam trap
Many exam-takers confuse vishing with pretexting, but vishing is the specific attack vector (voice call) while pretexting is the broader deception technique—the question asks for the type of attack, which is vishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
This is vishing (voice phishing) because the attacker uses a phone call to impersonate a trusted executive (the CFO) and manipulates the technician into bypassing MFA controls. The request to read back the one-time code is a classic social engineering tactic to capture a valid OTP, which the attacker can then use to authenticate as the CFO.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pretexting
Why it's wrong here
Pretexting is a social engineering tactic where the attacker invents a fabricated scenario—such as posing as a colleague, auditor, or vendor—to establish false legitimacy and manipulate the victim into revealing sensitive information. While the attacker here may indeed be using a pretext (e.g., impersonating a user or manager), this option does not specifically capture the voice-call delivery method. The question describes a live phone call with pressure, which is the defining characteristic of vishing; pretexting can occur over any communication channel, including email or in-person, so it is less precise than the correct answer.
- ✓
Vishing
Why this is correct
Vishing (voice phishing) is a form of social engineering conducted over the phone, where the attacker uses VoIP, caller ID spoofing, and a rehearsed script to impersonate a trusted entity and create a sense of urgency. In this scenario, a help desk technician receives a call from someone who is applying psychological pressure—a classic vishing tactic designed to bypass rational scrutiny and prompt quick, unverified action. The voice medium directly aligns with the definition of vishing, and because the attacker is leveraging the phone call itself to manipulate the technician, this is the most accurate and technically specific classification.
- ✗
Smishing
Why it's wrong here
Smishing (SMS phishing) is an attack that uses text messages, not live voice conversations, to deceive victims. The threat actor sends a malicious link or attachment via SMS, often disguised as a legitimate notification, to trick the recipient into downloading malware or visiting a phishing website. In the given scenario, the attacker is making a phone call in real time, which eliminates smishing as the correct answer because the delivery channel is voice, not text. Furthermore, smishing typically lacks the immediate interactive pressure described in the question, making it an incorrect but plausible distractor.
- ✗
Baiting
Why it's wrong here
Baiting is a social engineering attack that relies on offering a tempting lure—such as a free USB drive, an attractive download, or a fake prize—to entice the victim into performing a specific action that compromises security. Unlike the phone call described in the question, baiting usually involves physical media or digital downloads and does not require a live, interactive conversation. The attacker in this scenario is exerting pressure over the phone, not dangling a reward, so baiting does not match the attack pattern. This option is wrong because it confuses a lure-based attack with the direct voice-based manipulation of vishing.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.