Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A security analyst receives reports that several employees are being redirected to a fraudulent login page after typing the correct URL for a company application into their browser. Further investigation reveals that the company's internal DNS server has been compromised. Which type of attack best describes this scenario?

⚠ Common exam trap

Many exam-takers confuse pharming with phishing because both involve fake login pages, but pharming does not require the user to click a link—it subverts the DNS resolution process, making it a technical infrastructure attack rather than a social engineering one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Pharming

Pharming is correct because the attack redirects users from a legitimate website to a fraudulent one without their knowledge or interaction, typically by compromising the DNS resolution process. In this scenario, the internal DNS server has been compromised, so when employees type the correct URL, the DNS server returns the IP address of a fake login page instead of the real one. This is a classic example of DNS poisoning, a form of pharming.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing involves sending deceptive emails or messages that trick users into clicking malicious links or providing sensitive information. In this scenario, users typed the correct URL and were redirected, so no click on a malicious link occurred.

    When this WOULD be correct

    Phishing would be correct if the question described employees receiving fraudulent emails with links to a fake login page, without any mention of DNS compromise.

  • Spear phishing

    Why it's wrong here

    Spear phishing is a highly targeted form of phishing that uses personalized, context-aware emails or messages to convince a specific individual or small group to click a malicious link or attachment. The scenario describes numerous employees being redirected after typing the correct URL, which suggests a shared technical vulnerability rather than individually crafted malicious correspondence. Furthermore, no deceptive message, bespoke lure, or user interaction with a link is described, so spear phishing's essential characteristics are absent.

    When this WOULD be correct

    A security analyst finds that employees received personalized emails with a link to a fraudulent login page that mimics the company application, and the emails were crafted using information from social media. This would be spear phishing.

  • Pharming

    Why this is correct

    Pharming is an attack that manipulates the domain resolution process, typically by poisoning a DNS server or altering a local hosts file. When an employee enters the correct URL, the system receives a malicious IP address and silently lands on a fraudulent website, so no click on a poisoned link is required. Because this scenario explicitly mentions a DNS server compromise that redirects users system-wide, pharming directly matches the mechanism and scope described.

  • Vishing

    Why it's wrong here

    Vishing, or voice phishing, is a social engineering attack conducted over phone calls or VoIP, where attackers spoof caller ID and use urgency to trick victims into divulging credentials or PII. This incident contains no mention of voice communications, call transcripts, or interpersonal deception; instead, the redirection is caused by an infrastructure-level DNS compromise. Even if vishing could theoretically be combined with other attacks, the presented evidence points strictly to a network-layer technique, not a telephony-based one.

    When this WOULD be correct

    A security analyst receives reports that employees are getting fraudulent calls asking them to disclose their login credentials for a company application. Which type of attack best describes this scenario?

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

PharmingCorrect answer

Why this is correct

Pharming is an attack that manipulates the domain resolution process, typically by poisoning a DNS server or altering a local hosts file. When an employee enters the correct URL, the system receives a malicious IP address and silently lands on a fraudulent website, so no click on a poisoned link is required. Because this scenario explicitly mentions a DNS server compromise that redirects users system-wide, pharming directly matches the mechanism and scope described.

PhishingWrong answer — click to see why

Why this is wrong here

Phishing typically involves deceptive emails or messages to trick users into revealing credentials, not compromising a DNS server to redirect users to a fraudulent site.

★ When this WOULD be the correct answer

Phishing would be correct if the question described employees receiving fraudulent emails with links to a fake login page, without any mention of DNS compromise.

Why candidates choose this

Candidates may confuse pharming with phishing because both involve redirecting users to fake sites, but phishing relies on social engineering via messages, while pharming manipulates DNS or host files.

Spear phishingWrong answer — click to see why

Why this is wrong here

Spear phishing targets specific individuals via email, not DNS manipulation. The scenario involves DNS compromise redirecting users to a fake site, which is pharming.

★ When this WOULD be the correct answer

A security analyst finds that employees received personalized emails with a link to a fraudulent login page that mimics the company application, and the emails were crafted using information from social media. This would be spear phishing.

Why candidates choose this

Candidates may confuse targeted redirection (pharming) with targeted email attacks (spear phishing) because both involve deceiving users into entering credentials on fake pages.

VishingWrong answer — click to see why

Why this is wrong here

Vishing (voice phishing) uses phone calls or voice messages to trick victims, not DNS manipulation to redirect web traffic.

★ When this WOULD be the correct answer

A security analyst receives reports that employees are getting fraudulent calls asking them to disclose their login credentials for a company application. Which type of attack best describes this scenario?

Why candidates choose this

Candidates may confuse vishing with other phishing variants because all involve social engineering, but they overlook the technical mechanism (DNS compromise) that distinguishes pharming from voice-based attacks.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.