Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A person wearing a contractor badge asks reception to let them into the office because they forgot their access card and say they are expected for a server maintenance visit. What social engineering technique is most likely?

⚠ Common exam trap

The SY0-701 exam often tests the distinction between pretexting (fabricated scenario) and baiting (offering a lure), where candidates mistakenly choose baiting because they associate the 'forgotten card' with a 'bait' like a free item, but the core technique is the false identity and story.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Pretexting

Pretexting is correct because the attacker creates a fabricated scenario (the 'pretext') of being a contractor on a server maintenance visit to gain unauthorized physical access. The use of a contractor badge and the claim of a forgotten access card are designed to exploit the receptionist's trust and willingness to help, bypassing security controls without technical hacking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pretexting

    Why this is correct

    Pretexting is a social engineering technique where the attacker constructs a fabricated scenario or false identity to establish trust and gain unauthorized access. In this scenario, the contractor badge is the 'pretext' for an invented maintenance visit, and the claim of having forgotten their ID is a second layer designed to bypass reception's verification procedures. Unlike baiting, no material lure is involved; the entire attack relies on the plausibility of the story and the victim's willingness to help. This exploits the human tendency to comply with perceived authority or urgent requests, making it a direct physical access threat.

  • Baiting

    Why it's wrong here

    Baiting is a social engineering attack that relies on offering the target something tempting, such as a free USB drive, discounted software, or a charging cable, to trigger action. The attacker's goal is to entice the victim into inserting, downloading, or physically retrieving the object, which often carries malware or leads to credential capture. Here, the person at reception offers no such lure; they present a story about a scheduled maintenance task, so the distinction is that baiting appeals to greed or curiosity rather than manipulating trust or authority. It is a different failure mode because the victim must take possession of or interact with the bait.

  • Smishing

    Why it's wrong here

    Smishing (SMS phishing) is a vectored social engineering attack delivered exclusively through text messages, usually containing deceptive URLs or requests for personal information. It exploits mobile messaging trust and often uses urgent language to prompt immediate clicks, but it cannot describe an in-person conversation at a reception desk. The media mismatch is the core reason it is incorrect here: the scenario involves synchronous physical presence, not an asynchronous digital message. Since the attacker is physically presenting a badge, the attack vector is human contact, not SMS infrastructure.

  • Ransomware

    Why it's wrong here

    Ransomware is a type of malicious software that encrypts a victim's files or system and demands a ransom payment for decryption. It is a technical payload, not a social engineering narrative, and would be relevant long after initial access is achieved, e.g., if the attacker planted a USB later. The scenario describes the initial social engineering step to get past reception; ransomware has nothing to do with the ruse of a forgotten badge or contracting identity. Choosing this option would confuse a delivery mechanism with an attack phase, whereas pretexting is the actual tactic in play.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.