Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A help desk technician receives an SMS claiming to be from the mobile carrier. The message says the user's corporate number will be suspended unless they open a link and confirm an MFA code. The user has not reported any account issues. What attack is this?

⚠ Common exam trap

It's easy for candidates to confuse the delivery method (SMS vs. email vs. voice) — candidates often pick 'spear phishing' because the message is personalized, but the defining characteristic is the SMS channel, which makes it smishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing

Smishing is a phishing attack conducted via SMS (Short Message Service). The message impersonates the mobile carrier, creates urgency by threatening suspension, and lures the user to a malicious link to capture MFA codes or credentials. Since the attack vector is SMS, not email or voice, this is smishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Spear phishing

    Why it's wrong here

    Spear phishing is a socially engineered attack vector that leverages email or other messaging platforms with personalized information about the victim to increase credibility, often targeting specific individuals or organizations. In this scenario, the delivery channel is explicitly an SMS text message, and although the content uses urgency, it lacks the characteristic research-based personalization that defines spear phishing; the attack is instead mass-oriented, making smishing the correct classification.

  • Smishing

    Why this is correct

    Smishing is a form of phishing that uses Short Message Service (SMS) text messages as the attack vector, often impersonating trusted entities like mobile carriers to claim account suspension or unusual activity. The fraudulent link directs victims to a credential harvesting page or prompts them to provide one-time passcodes, compromising MFA protections. The urgency and carrier impersonation align precisely with smishing tactics.

  • Vishing

    Why it's wrong here

    Vishing, or voice phishing, relies on telephone calls or voice-over-IP systems, typically using a live caller or an automated voice response to create a sense of urgency and convince the victim to disclose sensitive data. The attacker in this case sends a text message containing a link, not a voice call, and no interactive voice element is present, so the attack falls outside the vishing definition.

  • Baiting

    Why it's wrong here

    Baiting is a social engineering technique that physically or digitally offers an enticing reward, such as a free USB drive, a prize, or a tempting download, to trick victims into installing malware or revealing credentials. Here, the attacker leverages a threat of service suspension rather than an attractive offer, and the primary mechanism is a text message link, not a physical or curiosity-driven lure, distinguishing it from baiting.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.