Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A procurement clerk receives a text message from someone claiming to be a supplier account manager. The message says a recent payment failed and asks the clerk to update bank details through a link to a secure portal. What should the clerk do first?

⚠ Common exam trap

Candidates often choose Option D, thinking that forwarding to finance is a safe escalation, but the SY0-701 exam emphasizes that the first step is always independent verification using a trusted method, not delegating or relying on the suspicious communication channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the request using a known supplier contact method before taking action

The clerk should independently verify the request using a known supplier contact method (e.g., a phone number on file) before taking any action. This prevents falling victim to a social engineering attack, such as a phishing or business email compromise (BEC) attempt, where the attacker spoofs the sender's identity to redirect payments. Verifying through an out-of-band channel ensures the request is legitimate, as the link in the message could lead to a credential-harvesting site or malware download.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Open the link and compare it with the supplier's branding

    Why it's wrong here

    Phishing sites and cloned vendor portals can perfectly replicate logos, fonts, and layouts using saved assets or browser-inspection tools. Additionally, the link itself may lead to a lookalike domain or a malicious credential-harvesting page, and interacting with it could trigger drive-by downloads or deliver a payload. Visual cues are presentation-layer only; they don't validate cryptographic identity, domain ownership, or the authenticity of the sender.

  • Reply to the text and ask the sender to confirm the request

    Why it's wrong here

    Since the original SMS is unsolicited and likely spoofed or from a compromised device, any response goes back to the attacker, who can then socially engineer further or use the reply to confirm a live number for future phishing. Even if the request appears genuine, the reply path is not an out-of-band channel; you're simply continuing the same unverified communication stream. True verification must use a separately established, independently known contact method, not the contact details embedded in the suspicious message.

  • Verify the request using a known supplier contact method before taking action

    Why this is correct

    The defining characteristic of social engineering / business email compromise (BEC) is that the attacker controls the communication channel, so the only robust countermeasure is to confirm the request via a channel that the attacker cannot influence — a phone number on file, a corporate address book entry, or a previously verified supplier portal. This breaks the attacker's control loop and ensures that the request is not acted upon solely on the basis of an unverified SMS. It also aligns with the principle of 'trust, but verify' and prevents invoice redirection or fraudulent payment before any harm occurs.

  • Forward the message to finance so they can decide whether it is legitimate

    Why it's wrong here

    Forwarding the message simply relocates an unverified request to another department; it does nothing to establish authenticity, and if the forwarded content contains malicious links or payloads, it may expose additional users to the same threat. Even if finance is responsible for payments, they would still be working from the same attacker-controlled information without independent verification. Proper incident handling would be to verify through a trusted channel first, and only escalate after confirmation failure or as part of a formal reporting process.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.