SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst receives a phone call from an individual claiming to be a member of the IT help desk. The caller states that an emergency security update requires the analyst's password immediately, and the request sounds urgent. The analyst notices the caller's voice is unfamiliar and the background noise is inconsistent with an office environment. Which type of social engineering attack is being attempted?
⚠ Common exam trap
A common mix-up: candidates confuse pretexting with vishing, but CompTIA distinguishes vishing as a subtype of social engineering that specifically uses voice technology, whereas pretexting is the broader act of fabricating an identity or scenario regardless of the communication channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
This is a vishing (voice phishing) attack because the threat actor uses a phone call to impersonate IT help desk personnel and pressures the analyst into disclosing sensitive credentials. Vishing specifically leverages voice communication to bypass email-based security controls and exploit human trust through urgency and authority.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering technique that is typically delivered via email, malicious links, or fraudulent websites, rather than through a real-time voice call. The attacker casts a wide net to trick victims into entering credentials or downloading malware, but because this specific attack uses the telephone as the attack vector, it falls under vishing (voice phishing) rather than generic phishing. While both rely on impersonation and urgency, the delivery channel is the defining factor in this scenario.
When this WOULD be correct
A security analyst receives an email that appears to be from the IT help desk, requesting password reset due to an emergency update. The email contains a link to a fake login page. This would be phishing.
- ✓
Vishing
Why this is correct
Vishing (voice phishing) is the correct answer because the attack uses a phone call to impersonate a legitimate entity and trick the victim into providing sensitive information, such as a password. The urgency and caller ID spoofing are common vishing tactics.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a highly targeted form of phishing that uses personalized details in an email or direct message to convince a specific high-value victim, such as an executive, to take a harmful action. Even if the caller on the phone knows the analyst's name or role, a phone call is not an email, and the attack does not involve a written message with a malicious payload. The correct classification for a voice-based impersonation attempt is vishing, because the attack vector and social engineering tactics are specific to telephony.
When this WOULD be correct
A security analyst receives a personalized email that appears to be from the IT help desk, addressing them by name and referencing their specific role, requesting password reset due to a security update. This targeted email attack would be spear phishing.
- ✗
Pretexting
Why it's wrong here
Pretexting involves creating a fabricated scenario (pretext) to obtain information, but it is a broader category that can be carried out via phone, email, or in person. However, when the attack is specifically conducted through a voice call, vishing is the more precise term used in cybersecurity. Pretexting is not incorrect in theory, but vishing is the standard classification for voice-based social engineering.
When this WOULD be correct
Pretexting would be correct if the scenario described an attacker impersonating a help desk technician who calls to verify account details by asking for the analyst's mother's maiden name or other personal information, without directly requesting a password, and uses that information to access the system later.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓VishingCorrect answer▾
Why this is correct
Vishing (voice phishing) is the correct answer because the attack uses a phone call to impersonate a legitimate entity and trick the victim into providing sensitive information, such as a password. The urgency and caller ID spoofing are common vishing tactics.
✗PhishingWrong answer — click to see why▾
Why this is wrong here
Phishing typically involves deceptive emails or websites, not phone calls. This scenario describes a voice-based attack, which is vishing.
★ When this WOULD be the correct answer
A security analyst receives an email that appears to be from the IT help desk, requesting password reset due to an emergency update. The email contains a link to a fake login page. This would be phishing.
Why candidates choose this
Candidates may broadly associate any social engineering attack that requests credentials with phishing, without distinguishing the delivery method (email vs. phone).
✗Spear phishingWrong answer — click to see why▾
Why this is wrong here
Spear phishing involves targeted, personalized emails or messages, not phone calls. The attack described uses a phone call, which is characteristic of vishing, not spear phishing.
★ When this WOULD be the correct answer
A security analyst receives a personalized email that appears to be from the IT help desk, addressing them by name and referencing their specific role, requesting password reset due to a security update. This targeted email attack would be spear phishing.
Why candidates choose this
Candidates may confuse spear phishing with vishing because both involve impersonation of a trusted entity, but they forget that spear phishing is exclusively a digital (email/message) attack, not a voice call.
✗PretextingWrong answer — click to see why▾
Why this is wrong here
Pretexting involves creating a fabricated scenario to obtain information, but the question specifically describes a phone call requesting a password, which is vishing (voice phishing). The attack is not pretexting because the caller is not establishing a false identity beyond claiming to be IT help desk; the primary threat is the phone-based phishing attempt.
★ When this WOULD be the correct answer
Pretexting would be correct if the scenario described an attacker impersonating a help desk technician who calls to verify account details by asking for the analyst's mother's maiden name or other personal information, without directly requesting a password, and uses that information to access the system later.
Why candidates choose this
Candidates may confuse pretexting with vishing because both involve impersonation and deception over the phone, but pretexting focuses on building a false narrative to extract information, while vishing is a direct phishing attempt via voice.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vishing
Vishing is a social engineering attack where criminals use phone calls or voice messages to trick victims into revealing sensitive information.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A help desk analyst receives a phone call from someone claiming to be the CFO, who says their phone was lost while traveling and requests an immediate MFA reset and temporary bypass for payroll access. The caller knows the CFO's last name and the company name, but cannot answer the callback verification question. What attack technique is most likely being used?
medium- A.Phishing
- ✓ B.Vishing
- C.Baiting
- D.Watering hole attack
Why B: The caller is using voice communication to impersonate a high-level executive (CFO) and manipulate the help desk analyst into bypassing security controls, which is the defining characteristic of vishing (voice phishing). The request for an MFA reset and temporary bypass is a social engineering tactic to exploit the analyst's authority bias and urgency, and the inability to pass callback verification confirms the caller is not legitimate.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.