Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A user forwards an email that says their payroll account will be disabled today unless they click a link and verify their password. The message uses the company logo, but the sender address is from a free webmail domain and the link goes to a look-alike login page. What type of attack is this?

⚠ Common exam trap

Many exam-takers confuse phishing with vishing or baiting because all involve social engineering, but the specific use of email with a fraudulent link to a fake login page is the defining characteristic of phishing, not voice calls (vishing) or physical lures (baiting).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing, because the attacker is using a fraudulent message to steal credentials.

This is a classic phishing attack because the attacker uses a fraudulent email that mimics a legitimate company to trick the user into clicking a link to a look-alike login page, with the goal of stealing their payroll credentials. The key indicators are the spoofed company logo, the free webmail sender address, and the fake login page, all of which are hallmarks of credential harvesting via phishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Baiting, because the attacker is offering something attractive to lure the user.

    Why it's wrong here

    Baiting typically relies on a physical lure, such as a free USB drive or a tempting download, that entices the user into an action that compromises the system. In this scenario, the attacker is not offering a tangible reward or a malware-laden device, but rather a deceptive message that impersonates a trusted source to harvest credentials. Therefore, baiting does not match the attack vector being described, as the core mechanism is fraudulent communication, not a seductive trap.

  • Phishing, because the attacker is using a fraudulent message to steal credentials.

    Why this is correct

    Phishing is the best match because the attacker is sending a deceptive message that impersonates a trusted source and directs the user to a fake login page. The goal is credential theft, and the urgency plus look-alike site are common signs. The sender address and request to verify a password are strong indicators of a phishing attempt.

  • Vishing, because the attacker is trying to trick the user into revealing information.

    Why it's wrong here

    Vishing is the voice-based counterpart of phishing, where the attacker uses a phone call or VoIP to trick the victim into revealing sensitive information. The email described in the question contains a web link and a fake login page, both of which are hallmarks of an email-based attack rather than a telephony-based one. Since the user forwarded an email and the attack involves URL navigation, vishing is not the correct classification for this security incident.

  • Impersonation, because the attacker is pretending to be someone from the company.

    Why it's wrong here

    Impersonation is a broad social engineering tactic where the attacker pretends to be a known individual, but it does not specify the medium or the goal of the attack. In this case, the attacker is using a fraudulent email to direct the victim to a phishing site, which is a classic phishing technique. While the sender may be impersonating a payroll department, the attack method is specifically a deceptive email campaign designed for credential theft, making phishing a more accurate and precise designation than generic impersonation.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.