Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A help desk technician receives an email that appears to come from the payroll provider. The message says the employee's direct deposit will be suspended unless they verify their account through a link. What type of attack is this?

⚠ Common exam trap

It's easy for candidates to confuse phishing with pretexting because both involve deception, but phishing is specifically electronic (email, SMS, or instant message), while pretexting relies on a fabricated story delivered through any medium, often requiring direct interaction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing

This is a classic phishing attack because the email impersonates a trusted entity (the payroll provider) and uses social engineering to trick the recipient into clicking a malicious link. Phishing specifically involves fraudulent electronic communications, such as email, to deceive victims into revealing sensitive information or installing malware. The attack vector here is email-based, which aligns directly with the definition of phishing in the SY0-701 domain of threats and vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why this is correct

    Correct because the message uses a fake urgent request to steal credentials through a link. It impersonates a trusted organization and pressures the user to act quickly. That combination is a classic phishing pattern, even if the wording seems professional and the logo looks real.

  • Baiting

    Why it's wrong here

    Baiting is a social engineering technique that tempts the target with an attractive lure—such as free media, a giveaway, or an infected USB drive—to exploit curiosity or desire for a reward. This email instead weaponizes urgency and fear, claiming account suspension to pressure a quick click, which are classic phishing triggers. Because the attack vector here is a malicious link impersonating a trusted organization rather than a tempting offer, the scenario does not meet the definition of baiting.

  • Vishing

    Why it's wrong here

    Vishing (voice phishing) is a social engineering attack conducted over telephone or voicemail systems, often using VoIP spoofing to impersonate a legitimate caller and extract sensitive information. The scenario explicitly describes an email message delivered asynchronously, with no voice interaction whatsoever. While the payload and psychological manipulation are similar to phishing, the channel is wrong, so vishing does not apply.

  • Pretexting

    Why it's wrong here

    Pretexting involves an attacker fabricating a detailed, believable story or persona to build trust and manipulate a victim into disclosing information or performing an action, often through a multi-step conversation. Although the email invents the pretext of a security issue, the attack's core is a deceptive link engineered to harvest credentials in a single interaction, which is the signature of phishing. Pretexting typically relies on sustained engagement and trust-building rather than a one-shot phishing lure, so it is a less accurate classification here.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An employee receives an email that appears to come from the HR team. It says their payroll account will be suspended unless they click a link and sign in within 30 minutes. What type of attack is this most likely?

easy
  • A.Smishing
  • B.Phishing
  • C.Vishing
  • D.Pretexting

Why B: This is a classic phishing attack because the threat actor uses a deceptive email message to trick the recipient into clicking a malicious link and providing sensitive credentials. Phishing specifically refers to social engineering attacks delivered via email, often leveraging urgency and impersonation of a trusted entity like HR to bypass the victim's critical thinking.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.