SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A procurement clerk receives a text message from someone claiming to be a supplier account manager. The message says a recent payment failed and asks the clerk to update bank details through a link to a secure portal. What should the clerk do first?
⚠ Common exam trap
Candidates often choose Option D, thinking that forwarding to finance is a safe escalation, but the SY0-701 exam emphasizes that the first step is always independent verification using a trusted method, not delegating or relying on the suspicious communication channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the request using a known supplier contact method before taking action
The clerk should independently verify the request using a known supplier contact method (e.g., a phone number on file) before taking any action. This prevents falling victim to a social engineering attack, such as a phishing or business email compromise (BEC) attempt, where the attacker spoofs the sender's identity to redirect payments. Verifying through an out-of-band channel ensures the request is legitimate, as the link in the message could lead to a credential-harvesting site or malware download.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open the link and compare it with the supplier's branding
Why it's wrong here
Phishing sites and cloned vendor portals can perfectly replicate logos, fonts, and layouts using saved assets or browser-inspection tools. Additionally, the link itself may lead to a lookalike domain or a malicious credential-harvesting page, and interacting with it could trigger drive-by downloads or deliver a payload. Visual cues are presentation-layer only; they don't validate cryptographic identity, domain ownership, or the authenticity of the sender.
- ✗
Reply to the text and ask the sender to confirm the request
Why it's wrong here
Since the original SMS is unsolicited and likely spoofed or from a compromised device, any response goes back to the attacker, who can then socially engineer further or use the reply to confirm a live number for future phishing. Even if the request appears genuine, the reply path is not an out-of-band channel; you're simply continuing the same unverified communication stream. True verification must use a separately established, independently known contact method, not the contact details embedded in the suspicious message.
- ✓
Verify the request using a known supplier contact method before taking action
Why this is correct
The defining characteristic of social engineering / business email compromise (BEC) is that the attacker controls the communication channel, so the only robust countermeasure is to confirm the request via a channel that the attacker cannot influence — a phone number on file, a corporate address book entry, or a previously verified supplier portal. This breaks the attacker's control loop and ensures that the request is not acted upon solely on the basis of an unverified SMS. It also aligns with the principle of 'trust, but verify' and prevents invoice redirection or fraudulent payment before any harm occurs.
- ✗
Forward the message to finance so they can decide whether it is legitimate
Why it's wrong here
Forwarding the message simply relocates an unverified request to another department; it does nothing to establish authenticity, and if the forwarded content contains malicious links or payloads, it may expose additional users to the same threat. Even if finance is responsible for payments, they would still be working from the same attacker-controlled information without independent verification. Proper incident handling would be to verify through a trusted channel first, and only escalate after confirmation failure or as part of a formal reporting process.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.