SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A user forwards an email that says a shared document is available and must be reviewed within 10 minutes. The display name looks like a trusted vendor, but the Reply-To address points to a free webmail account. Which two details are strongest indicators that this is a phishing attempt? Select two.
⚠ Common exam trap
CompTIA often tests the distinction between easily spoofed visual elements (logos, formatting) and verifiable technical indicators (Reply-To domain mismatch, urgency cues) to catch candidates who rely on superficial appearance rather than email authentication mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The message creates a short deadline and pressures the user to act quickly.
Phishing attacks frequently use urgency and time pressure to bypass the victim's rational analysis, exploiting the psychological principle of scarcity to trigger impulsive clicks. The 10-minute deadline is a classic social engineering tactic to prevent the user from verifying the email's legitimacy through normal channels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The message creates a short deadline and pressures the user to act quickly.
Why this is correct
Urgency is a classic phishing tactic because it pushes recipients to react before verifying the request. A short deadline increases the chance that the user clicks a link or shares credentials without checking the sender or context.
- ✓
The Reply-To address uses a free webmail domain instead of the vendor's corporate domain.
Why this is correct
A mismatched Reply-To address is a strong technical indicator of phishing because SMTP allows the From header to display a spoofed identity while the Reply-To header controls where replies actually arrive. Attackers routinely set a believable display name and corporate domain in From, then redirect replies to a free webmail inbox they control. This breaks the assumed correspondence between sender and recipient of responses, and it exposes the message as an impersonation attempt even though the visible sender looks legitimate.
- ✗
The message includes the company's logo and professional-looking formatting.
Why it's wrong here
Seeing the company's logo and polished HTML formatting does not authenticate the message, because email headers and body content are created by the sender and are trivially copied from a legitimate newsletter or portal. Phishing kits often include cloned templates with original logos, CSS, and even footers, making the email appear routine to recipients and bypassing filters that rely on visual similarity. Legitimacy must be verified through the sending infrastructure and signing protocols like SPF, DKIM, and DMARC, not visual appearance.
- ✗
The email refers to a shared document that the user should review.
Why it's wrong here
A request to review a shared document is also present in enormous volumes of legitimate business email, so by itself it carries no malicious signal. Attackers choose common, plausible business topics to increase the chance the recipient's guard is down; the harm comes from the embedded link or attachment, not from the subject line. Without other indicators such as unusual URLs, spoofed domains, or urgency, this phrase is not diagnostic of phishing.
- ✗
The message was received during normal business hours.
Why it's wrong here
The arrival time during normal business hours is not a valid authenticity check because threat actors schedule and send phishing campaigns to overlap with typical work schedules, and automated mail systems are capable of sending at any time. An attacker leveraging compromised infrastructure and mail relays can time delivery precisely to exploit peak attention. Therefore, time of day has no forensic or behavioral value in distinguishing a malicious message from legitimate correspondence.
Go deeper
Related to this question
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.