SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A help desk technician reviews a voicemail in which the caller claims to be from the security team, says the user will be locked out unless they read back a one-time passcode, and leaves a callback number. What type of attack is this?
⚠ Common exam trap
Test-takers frequently confuse vishing with smishing because both involve social engineering over digital communication, but the key differentiator is the medium: voice (voicemail/call) versus text message (SMS).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing, because the attacker is using voice communication to pressure the user.
Vishing (voice phishing) uses voice communication—such as phone calls or voicemails—to trick victims into revealing sensitive information. In this scenario, the attacker leaves a voicemail claiming to be from the security team and pressures the user to read back a one-time passcode, which is a classic vishing tactic that exploits trust and urgency over voice channels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smishing, because the attacker is using a text message with a link.
Why it's wrong here
Smishing is specifically SMS-based phishing, where the attack is delivered via text message and typically contains a malicious link or attachment. In this scenario, the attacker communicates through voicemail, which is an audio channel, not an SMS payload. Even if the voicemail instructs the user to call back or read a one-time passcode, the delivery medium remains voice, so smishing is the incorrect classification.
- ✓
Vishing, because the attacker is using voice communication to pressure the user.
Why this is correct
Vishing is voice-based social engineering, including phone calls and voicemail messages that try to pressure the target into revealing information. Requesting a one-time passcode is especially dangerous because it can let an attacker bypass MFA protections. The callback number is often used to appear legitimate and keep the victim engaged long enough to disclose sensitive data.
- ✗
Baiting, because the attacker is offering a reward to entice the user.
Why it's wrong here
Baiting relies on an enticing physical or digital lure—such as free media, a found USB drive, or a fraudulent reward—that triggers the victim's curiosity or greed. The voicemail in this scenario does not offer a reward; it creates a false sense of urgency by claiming a verification is needed and requesting a one-time passcode. Since the social engineering lever is pressure, not temptation, the attack category is not baiting.
- ✗
Pretexting, because the attacker invented a role and story.
Why it's wrong here
Pretexting describes the fabricated role and story the attacker uses to establish credibility, which is certainly present in this voicemail. However, Security+ categories are determined by the primary communication channel, and this attack uses voice (voicemail), making vishing the more precise classification. Pretexting could occur via email, in-person, or phone, so naming it alone fails to capture that the attacker is exploiting telephony to extract an OTP and bypass MFA.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Vishing
Vishing is a social engineering attack where criminals use phone calls or voice messages to trick victims into revealing sensitive information.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.