Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security analyst receives a phone call from an individual claiming to be a member of the IT help desk. The caller states that an emergency security update requires the analyst's password immediately, and the request sounds urgent. The analyst notices the caller's voice is unfamiliar and the background noise is inconsistent with an office environment. Which type of social engineering attack is being attempted?

⚠ Common exam trap

A common mix-up: candidates confuse pretexting with vishing, but CompTIA distinguishes vishing as a subtype of social engineering that specifically uses voice technology, whereas pretexting is the broader act of fabricating an identity or scenario regardless of the communication channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vishing

This is a vishing (voice phishing) attack because the threat actor uses a phone call to impersonate IT help desk personnel and pressures the analyst into disclosing sensitive credentials. Vishing specifically leverages voice communication to bypass email-based security controls and exploit human trust through urgency and authority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing is a social engineering technique that is typically delivered via email, malicious links, or fraudulent websites, rather than through a real-time voice call. The attacker casts a wide net to trick victims into entering credentials or downloading malware, but because this specific attack uses the telephone as the attack vector, it falls under vishing (voice phishing) rather than generic phishing. While both rely on impersonation and urgency, the delivery channel is the defining factor in this scenario.

    When this WOULD be correct

    A security analyst receives an email that appears to be from the IT help desk, requesting password reset due to an emergency update. The email contains a link to a fake login page. This would be phishing.

  • Vishing

    Why this is correct

    Vishing (voice phishing) is the correct answer because the attack uses a phone call to impersonate a legitimate entity and trick the victim into providing sensitive information, such as a password. The urgency and caller ID spoofing are common vishing tactics.

  • Spear phishing

    Why it's wrong here

    Spear phishing is a highly targeted form of phishing that uses personalized details in an email or direct message to convince a specific high-value victim, such as an executive, to take a harmful action. Even if the caller on the phone knows the analyst's name or role, a phone call is not an email, and the attack does not involve a written message with a malicious payload. The correct classification for a voice-based impersonation attempt is vishing, because the attack vector and social engineering tactics are specific to telephony.

    When this WOULD be correct

    A security analyst receives a personalized email that appears to be from the IT help desk, addressing them by name and referencing their specific role, requesting password reset due to a security update. This targeted email attack would be spear phishing.

  • Pretexting

    Why it's wrong here

    Pretexting involves creating a fabricated scenario (pretext) to obtain information, but it is a broader category that can be carried out via phone, email, or in person. However, when the attack is specifically conducted through a voice call, vishing is the more precise term used in cybersecurity. Pretexting is not incorrect in theory, but vishing is the standard classification for voice-based social engineering.

    When this WOULD be correct

    Pretexting would be correct if the scenario described an attacker impersonating a help desk technician who calls to verify account details by asking for the analyst's mother's maiden name or other personal information, without directly requesting a password, and uses that information to access the system later.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

VishingCorrect answer

Why this is correct

Vishing (voice phishing) is the correct answer because the attack uses a phone call to impersonate a legitimate entity and trick the victim into providing sensitive information, such as a password. The urgency and caller ID spoofing are common vishing tactics.

PhishingWrong answer — click to see why

Why this is wrong here

Phishing typically involves deceptive emails or websites, not phone calls. This scenario describes a voice-based attack, which is vishing.

★ When this WOULD be the correct answer

A security analyst receives an email that appears to be from the IT help desk, requesting password reset due to an emergency update. The email contains a link to a fake login page. This would be phishing.

Why candidates choose this

Candidates may broadly associate any social engineering attack that requests credentials with phishing, without distinguishing the delivery method (email vs. phone).

Spear phishingWrong answer — click to see why

Why this is wrong here

Spear phishing involves targeted, personalized emails or messages, not phone calls. The attack described uses a phone call, which is characteristic of vishing, not spear phishing.

★ When this WOULD be the correct answer

A security analyst receives a personalized email that appears to be from the IT help desk, addressing them by name and referencing their specific role, requesting password reset due to a security update. This targeted email attack would be spear phishing.

Why candidates choose this

Candidates may confuse spear phishing with vishing because both involve impersonation of a trusted entity, but they forget that spear phishing is exclusively a digital (email/message) attack, not a voice call.

PretextingWrong answer — click to see why

Why this is wrong here

Pretexting involves creating a fabricated scenario to obtain information, but the question specifically describes a phone call requesting a password, which is vishing (voice phishing). The attack is not pretexting because the caller is not establishing a false identity beyond claiming to be IT help desk; the primary threat is the phone-based phishing attempt.

★ When this WOULD be the correct answer

Pretexting would be correct if the scenario described an attacker impersonating a help desk technician who calls to verify account details by asking for the analyst's mother's maiden name or other personal information, without directly requesting a password, and uses that information to access the system later.

Why candidates choose this

Candidates may confuse pretexting with vishing because both involve impersonation and deception over the phone, but pretexting focuses on building a false narrative to extract information, while vishing is a direct phishing attempt via voice.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A help desk analyst receives a phone call from someone claiming to be the CFO, who says their phone was lost while traveling and requests an immediate MFA reset and temporary bypass for payroll access. The caller knows the CFO's last name and the company name, but cannot answer the callback verification question. What attack technique is most likely being used?

medium
  • A.Phishing
  • B.Vishing
  • C.Baiting
  • D.Watering hole attack

Why B: The caller is using voice communication to impersonate a high-level executive (CFO) and manipulate the help desk analyst into bypassing security controls, which is the defining characteristic of vishing (voice phishing). The request for an MFA reset and temporary bypass is a social engineering tactic to exploit the analyst's authority bias and urgency, and the inability to pass callback verification confirms the caller is not legitimate.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.