Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A user receives a phone call from someone who claims to be a member of the company's IT support team. The caller states that the user's account has been compromised and requests the user's username, password, and the current multi-factor authentication (MFA) code to 'verify identity and secure the account.' Which type of social engineering attack is being attempted?

⚠ Common exam trap

Many exam-takers confuse vishing with pretexting, as both involve deception, but vishing specifically uses voice (phone) as the attack vector, while pretexting is a broader category that can occur through any communication channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vishing

B is correct because vishing (voice phishing) is a social engineering attack conducted over the phone, where the attacker impersonates a trusted entity (IT support) to trick the victim into revealing sensitive information such as credentials and MFA codes. The request for the current MFA code is a key indicator, as it would allow the attacker to bypass multi-factor authentication in real time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Spear phishing

    Why it's wrong here

    Spear phishing is a targeted cyberattack that occurs via email or electronic messaging, in which the attacker customizes the content for a specific victim or organization to increase credibility, often enticing the victim to click a malicious link or open an attachment. The attack vector relies on digital text-based communication that can be filtered or analyzed by security tools. In this scenario, the communication channel is a phone call, not email; hence, while the attacker may use a pretext, the lack of any link, attachment, or email component makes spear phishing technically inapplicable, and vishing is the correct voice-specific term.

    When this WOULD be correct

    Spear phishing would be correct if the question described a targeted email that appears to come from a trusted source (e.g., IT support) and asks the recipient to click a link or provide credentials via a fake login page.

  • Vishing

    Why this is correct

    Vishing (voice phishing) is a social engineering attack executed over phone calls or Voice over IP (VoIP), where the attacker impersonates a trusted authority—such as IT support, a bank, or a government agency—to manipulate the victim into revealing sensitive data like passwords, PINs, or one-time MFA codes. This scenario explicitly involves a phone call, which directly aligns with the definition of vishing. The attacker leverages the voice channel to establish urgency and bypass email-based security defenses, making vishing the precise classification under CompTIA Security+.

  • Pretexting

    Why it's wrong here

    Pretexting is the act of creating a fabricated scenario (pretext) to obtain information, and it can be used across different communication channels. While the attacker does use a pretext in this scenario, 'vishing' is the more specific term when the attack occurs via phone. In the context of CompTIA Security+, vishing is the best answer because it directly identifies the medium (voice).

    When this WOULD be correct

    Pretexting would be correct if the question described an attacker using a fabricated identity or story (e.g., posing as a vendor or auditor) to obtain information via email, in person, or other means, without specifying the communication channel as voice.

  • Tailgating

    Why it's wrong here

    Tailgating is a physical security attack in which an unauthorized person follows an authorized individual through a secured entrance, doorway, or checkpoint to gain entry without presenting their own credentials. This attack requires in-person presence at a restricted facility and typically exploits the authorized person's courtesy or inattention to access control measures. Because the scenario involves a phone call rather than physical proximity, tailgating cannot occur; the attacker is not physically following anyone, but is conducting a remote social engineering attempt.

    When this WOULD be correct

    A question describes an attacker physically following an employee through a secured door without using their own badge, exploiting the employee's courtesy to gain access to a building.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

VishingCorrect answer

Why this is correct

Vishing (voice phishing) is a social engineering attack executed over phone calls or Voice over IP (VoIP), where the attacker impersonates a trusted authority—such as IT support, a bank, or a government agency—to manipulate the victim into revealing sensitive data like passwords, PINs, or one-time MFA codes. This scenario explicitly involves a phone call, which directly aligns with the definition of vishing. The attacker leverages the voice channel to establish urgency and bypass email-based security defenses, making vishing the precise classification under CompTIA Security+.

Spear phishingWrong answer — click to see why

Why this is wrong here

Spear phishing is a targeted email attack, not a phone call. The question describes a voice-based attack (phone call), which is vishing, not spear phishing.

★ When this WOULD be the correct answer

Spear phishing would be correct if the question described a targeted email that appears to come from a trusted source (e.g., IT support) and asks the recipient to click a link or provide credentials via a fake login page.

Why candidates choose this

Candidates may confuse spear phishing with vishing because both are targeted attacks that impersonate a trusted entity, but they forget that spear phishing is specifically email-based, not voice-based.

PretextingWrong answer — click to see why

Why this is wrong here

Pretexting involves fabricating a scenario to obtain information, but the specific attack vector here is voice-based (phone call), making 'vishing' the more precise term. The question explicitly describes a phone call, which is the defining characteristic of vishing.

★ When this WOULD be the correct answer

Pretexting would be correct if the question described an attacker using a fabricated identity or story (e.g., posing as a vendor or auditor) to obtain information via email, in person, or other means, without specifying the communication channel as voice.

Why candidates choose this

Candidates may confuse pretexting with vishing because both involve deception and identity fabrication. They might focus on the 'false identity' aspect (IT support) and overlook that the phone call makes it specifically vishing.

TailgatingWrong answer — click to see why

Why this is wrong here

Tailgating involves an unauthorized person physically following an authorized individual into a restricted area without proper authentication, not a phone call requesting credentials.

★ When this WOULD be the correct answer

A question describes an attacker physically following an employee through a secured door without using their own badge, exploiting the employee's courtesy to gain access to a building.

Why candidates choose this

Candidates may confuse tailgating with any attack that bypasses security controls, but tailgating specifically refers to physical access, not social engineering over the phone.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.