Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SOC analyst is investigating an alert triggered when a user clicked a link in an email. The email appeared to be from a trusted vendor and included a PDF attachment with a macro, but the user did not run the macro. Upon reviewing the email headers, the analyst notices that the sender's domain is a common misspelling of the vendor's legitimate domain. Which of the following is the most direct indicator that this email is a phishing attempt?

⚠ Common exam trap

CompTIA often tests the distinction between a potential threat (like an unexecuted macro) and an actual indicator of an attack (like a spoofed domain in headers), trapping candidates who focus on the payload rather than the evidence of impersonation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The misspelled sender domain in the email headers

The misspelled sender domain in the email headers is the most direct indicator of a phishing attempt because it reveals the attacker's use of domain spoofing or a lookalike domain to impersonate a trusted vendor. This is a classic social engineering technique that bypasses the user's visual inspection, and since the user did not run the macro, the macro itself is not an active threat. The email headers provide forensic evidence of the domain mismatch, which is a definitive sign of phishing regardless of user actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The macro embedded in the PDF attachment

    Why it's wrong here

    A macro can be malicious, but in this scenario the user did not run it, so it is not an active indicator of the phishing attempt. The presence of a macro is not itself proof of phishing, as legitimate documents may contain macros.

    When this WOULD be correct

    In a scenario where a user reports a suspicious email attachment and the SOC analyst finds that the attachment contains a macro that auto-executes or is known to be malicious, the macro itself would be the direct indicator of a phishing attempt.

  • The misspelled sender domain in the email headers

    Why this is correct

    This is the strongest indicator because it directly shows the email's origin is fraudulent. Attackers register domains that are visually similar to legitimate ones to trick users. The domain mismatch confirms the email is not from the vendor.

  • The alert generated by the user clicking the link

    Why it's wrong here

    The alert is a log entry generated by a detection mechanism (e.g., an email gateway or endpoint agent) after the user clicked the embedded URL; it is an effect of the user's action, not an inherent property of the email or link. Clicking a link is a necessary but not sufficient condition for phishing — many legitimate emails contain hyperlinks, and a click event alone does not reveal whether the destination is malicious. Moreover, the alert could be a false positive triggered by a benign URL categorizer or a sandbox, so the analyst must correlate it with other evidence such as the sender domain, URL reputation, or payload behavior. Thus, while it serves as a trigger for investigation, it lacks the evidentiary weight of the domain mismatch.

    When this WOULD be correct

    This option would be correct in a question asking: 'Which of the following is the most direct indicator that a user's action has triggered a security incident?' or 'What is the first sign that a security event has occurred?'

  • The email appeared to be from a known vendor

    Why it's wrong here

    Phishing emails often impersonate trusted organizations to gain credibility. However, the email only 'appears' to be from the vendor; the domain misspelling reveals the deception. The appearance alone is not an indicator without supporting evidence.

    When this WOULD be correct

    This option would be correct in a question asking: 'Which social engineering principle is being exploited when an email claims to be from a known vendor to gain trust?' In that context, the appearance of a known vendor directly indicates the use of authority or familiarity.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

The misspelled sender domain in the email headersCorrect answer

Why this is correct

This is the strongest indicator because it directly shows the email's origin is fraudulent. Attackers register domains that are visually similar to legitimate ones to trick users. The domain mismatch confirms the email is not from the vendor.

The macro embedded in the PDF attachmentWrong answer — click to see why

Why this is wrong here

The macro was not executed by the user, so it is not a direct indicator of phishing in this alert; the misspelled domain is a more immediate red flag.

★ When this WOULD be the correct answer

In a scenario where a user reports a suspicious email attachment and the SOC analyst finds that the attachment contains a macro that auto-executes or is known to be malicious, the macro itself would be the direct indicator of a phishing attempt.

Why candidates choose this

Candidates often associate macros with phishing, but overlook that the macro was not run, making it a potential threat rather than a direct indicator in this context.

The alert generated by the user clicking the linkWrong answer — click to see why

Why this is wrong here

The alert is a consequence of the user's action, not a direct indicator of phishing. The question asks for the most direct indicator that the email itself is a phishing attempt, and the alert is a system response, not a characteristic of the email.

★ When this WOULD be the correct answer

This option would be correct in a question asking: 'Which of the following is the most direct indicator that a user's action has triggered a security incident?' or 'What is the first sign that a security event has occurred?'

Why candidates choose this

Candidates may confuse the alert (the system's detection mechanism) with the actual evidence of phishing, thinking that any triggered alert directly indicates the nature of the threat, rather than understanding that the alert is a result of policy-based detection.

The email appeared to be from a known vendorWrong answer — click to see why

Why this is wrong here

The email appearing to be from a known vendor is not a direct indicator of phishing; attackers often spoof trusted names. The misspelled domain in the headers is the actual evidence of impersonation.

★ When this WOULD be the correct answer

This option would be correct in a question asking: 'Which social engineering principle is being exploited when an email claims to be from a known vendor to gain trust?' In that context, the appearance of a known vendor directly indicates the use of authority or familiarity.

Why candidates choose this

Candidates may think that any email claiming to be from a trusted source is suspicious, but here the question asks for the most direct indicator, and the misspelled domain is more concrete evidence than the mere appearance of a known vendor.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.