SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst receives reports that several employees are being redirected to a fraudulent login page after typing the correct URL for a company application into their browser. Further investigation reveals that the company's internal DNS server has been compromised. Which type of attack best describes this scenario?
⚠ Common exam trap
Many exam-takers confuse pharming with phishing because both involve fake login pages, but pharming does not require the user to click a link—it subverts the DNS resolution process, making it a technical infrastructure attack rather than a social engineering one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pharming
Pharming is correct because the attack redirects users from a legitimate website to a fraudulent one without their knowledge or interaction, typically by compromising the DNS resolution process. In this scenario, the internal DNS server has been compromised, so when employees type the correct URL, the DNS server returns the IP address of a fake login page instead of the real one. This is a classic example of DNS poisoning, a form of pharming.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing involves sending deceptive emails or messages that trick users into clicking malicious links or providing sensitive information. In this scenario, users typed the correct URL and were redirected, so no click on a malicious link occurred.
When this WOULD be correct
Phishing would be correct if the question described employees receiving fraudulent emails with links to a fake login page, without any mention of DNS compromise.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a highly targeted form of phishing that uses personalized, context-aware emails or messages to convince a specific individual or small group to click a malicious link or attachment. The scenario describes numerous employees being redirected after typing the correct URL, which suggests a shared technical vulnerability rather than individually crafted malicious correspondence. Furthermore, no deceptive message, bespoke lure, or user interaction with a link is described, so spear phishing's essential characteristics are absent.
When this WOULD be correct
A security analyst finds that employees received personalized emails with a link to a fraudulent login page that mimics the company application, and the emails were crafted using information from social media. This would be spear phishing.
- ✓
Pharming
Why this is correct
Pharming is an attack that manipulates the domain resolution process, typically by poisoning a DNS server or altering a local hosts file. When an employee enters the correct URL, the system receives a malicious IP address and silently lands on a fraudulent website, so no click on a poisoned link is required. Because this scenario explicitly mentions a DNS server compromise that redirects users system-wide, pharming directly matches the mechanism and scope described.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a social engineering attack conducted over phone calls or VoIP, where attackers spoof caller ID and use urgency to trick victims into divulging credentials or PII. This incident contains no mention of voice communications, call transcripts, or interpersonal deception; instead, the redirection is caused by an infrastructure-level DNS compromise. Even if vishing could theoretically be combined with other attacks, the presented evidence points strictly to a network-layer technique, not a telephony-based one.
When this WOULD be correct
A security analyst receives reports that employees are getting fraudulent calls asking them to disclose their login credentials for a company application. Which type of attack best describes this scenario?
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓PharmingCorrect answer▾
Why this is correct
Pharming is an attack that manipulates the domain resolution process, typically by poisoning a DNS server or altering a local hosts file. When an employee enters the correct URL, the system receives a malicious IP address and silently lands on a fraudulent website, so no click on a poisoned link is required. Because this scenario explicitly mentions a DNS server compromise that redirects users system-wide, pharming directly matches the mechanism and scope described.
✗PhishingWrong answer — click to see why▾
Why this is wrong here
Phishing typically involves deceptive emails or messages to trick users into revealing credentials, not compromising a DNS server to redirect users to a fraudulent site.
★ When this WOULD be the correct answer
Phishing would be correct if the question described employees receiving fraudulent emails with links to a fake login page, without any mention of DNS compromise.
Why candidates choose this
Candidates may confuse pharming with phishing because both involve redirecting users to fake sites, but phishing relies on social engineering via messages, while pharming manipulates DNS or host files.
✗Spear phishingWrong answer — click to see why▾
Why this is wrong here
Spear phishing targets specific individuals via email, not DNS manipulation. The scenario involves DNS compromise redirecting users to a fake site, which is pharming.
★ When this WOULD be the correct answer
A security analyst finds that employees received personalized emails with a link to a fraudulent login page that mimics the company application, and the emails were crafted using information from social media. This would be spear phishing.
Why candidates choose this
Candidates may confuse targeted redirection (pharming) with targeted email attacks (spear phishing) because both involve deceiving users into entering credentials on fake pages.
✗VishingWrong answer — click to see why▾
Why this is wrong here
Vishing (voice phishing) uses phone calls or voice messages to trick victims, not DNS manipulation to redirect web traffic.
★ When this WOULD be the correct answer
A security analyst receives reports that employees are getting fraudulent calls asking them to disclose their login credentials for a company application. Which type of attack best describes this scenario?
Why candidates choose this
Candidates may confuse vishing with other phishing variants because all involve social engineering, but they overlook the technical mechanism (DNS compromise) that distinguishes pharming from voice-based attacks.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Application Attacks: SQL Injection, XSS
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.