Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security analyst is reviewing logs after a successful phishing attack. The attacker used a fake login page that mimicked the company's single sign-on portal to harvest usernames and passwords. The attacker then used the stolen credentials to access the corporate email system. Which type of attack best describes the initial compromise?

⚠ Common exam trap

Watch out — candidates often confuse credential harvesting via phishing with an on-path attack, because both involve intercepting credentials, but phishing relies on user deception to voluntarily submit credentials, whereas an on-path attack captures them transparently during an existing session.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Credential harvesting via phishing

The initial compromise was achieved by luring the victim to a fake login page that mimicked the company's single sign-on portal, which is a classic phishing technique. The attacker harvested the credentials directly from the user's submission, making this a credential harvesting attack via phishing. This aligns with the definition of phishing as a social engineering attack that uses deception to obtain sensitive information, distinct from brute-force or password spraying which rely on guessing or trying multiple passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • On-path attack

    Why it's wrong here

    Incorrect. An on-path (formerly man-in-the-middle) attack involves the attacker intercepting and possibly altering communications between two parties. In this scenario, the attacker hosted a fake login page that the victims visited directly; there is no indication of intercepted traffic between the user and the legitimate service.

    When this WOULD be correct

    An on-path attack would be correct if the question described an attacker intercepting network traffic (e.g., ARP spoofing or man-in-the-middle) to capture credentials or modify data in transit, without using a fake login page.

  • Credential harvesting via phishing

    Why this is correct

    Correct. The attacker used a deceptive email or website to trick users into voluntarily entering their credentials. This is the defining characteristic of phishing-based credential harvesting. The stolen credentials were then reused to access the corporate email system.

  • Brute-force attack

    Why it's wrong here

    A brute-force attack is an automated, systematic trial-and-error method where an attacker submits many password combinations (often using tools like Hydra or John the Ripper) against an authentication endpoint until one succeeds. In this scenario, the attacker did not guess credentials but instead used a deceptive phishing page to trick users into voluntarily submitting their passwords. The defining element is social engineering, not computational guessing, so classifying this as brute-force would misidentify the attack vector and undermine the correct mitigation strategy.

    When this WOULD be correct

    A question describing an attacker repeatedly trying different passwords against a single account until successful, such as 'An attacker gains access to a user account by trying thousands of password combinations in a short period.'

  • Password spraying

    Why it's wrong here

    Incorrect. Password spraying attempts a small number of commonly used passwords against a large number of accounts. The scenario involves a targeted attack that harvested credentials from multiple users via a fake login page, not a low-and-slow password guessing technique.

    When this WOULD be correct

    A security analyst notices multiple failed login attempts using the same password (e.g., 'Spring2024!') across hundreds of user accounts within a short time frame. This indicates a password spraying attack.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Credential harvesting via phishingCorrect answer

Why this is correct

Correct. The attacker used a deceptive email or website to trick users into voluntarily entering their credentials. This is the defining characteristic of phishing-based credential harvesting. The stolen credentials were then reused to access the corporate email system.

On-path attackWrong answer — click to see why

Why this is wrong here

The initial compromise was achieved through a fake login page that harvested credentials, which is credential harvesting via phishing, not an on-path attack. An on-path attack involves intercepting or modifying communications between two parties, not tricking users into entering credentials on a fake site.

★ When this WOULD be the correct answer

An on-path attack would be correct if the question described an attacker intercepting network traffic (e.g., ARP spoofing or man-in-the-middle) to capture credentials or modify data in transit, without using a fake login page.

Why candidates choose this

Candidates may confuse on-path attacks with phishing because both involve credential theft, but on-path attacks focus on intercepting live traffic rather than deceiving users into entering credentials on a fake site.

Brute-force attackWrong answer — click to see why

Why this is wrong here

The initial compromise was achieved through a fake login page that harvested credentials, not by systematically guessing passwords. Brute-force attacks involve automated guessing of many password combinations, which is not described here.

★ When this WOULD be the correct answer

A question describing an attacker repeatedly trying different passwords against a single account until successful, such as 'An attacker gains access to a user account by trying thousands of password combinations in a short period.'

Why candidates choose this

Candidates may confuse credential harvesting with password guessing, or assume that any attack involving passwords is a brute-force attack, overlooking the phishing vector.

Password sprayingWrong answer — click to see why

Why this is wrong here

Password spraying involves trying a few common passwords against many accounts, not using a fake login page to harvest credentials from a single phishing attack.

★ When this WOULD be the correct answer

A security analyst notices multiple failed login attempts using the same password (e.g., 'Spring2024!') across hundreds of user accounts within a short time frame. This indicates a password spraying attack.

Why candidates choose this

Candidates may confuse password spraying with credential harvesting because both involve obtaining passwords, but they overlook the distinct method of using a fake login page in phishing.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.