SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A user receives a phone call from someone who claims to be a member of the company's IT support team. The caller states that the user's account has been compromised and requests the user's username, password, and the current multi-factor authentication (MFA) code to 'verify identity and secure the account.' Which type of social engineering attack is being attempted?
⚠ Common exam trap
Many exam-takers confuse vishing with pretexting, as both involve deception, but vishing specifically uses voice (phone) as the attack vector, while pretexting is a broader category that can occur through any communication channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
B is correct because vishing (voice phishing) is a social engineering attack conducted over the phone, where the attacker impersonates a trusted entity (IT support) to trick the victim into revealing sensitive information such as credentials and MFA codes. The request for the current MFA code is a key indicator, as it would allow the attacker to bypass multi-factor authentication in real time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted cyberattack that occurs via email or electronic messaging, in which the attacker customizes the content for a specific victim or organization to increase credibility, often enticing the victim to click a malicious link or open an attachment. The attack vector relies on digital text-based communication that can be filtered or analyzed by security tools. In this scenario, the communication channel is a phone call, not email; hence, while the attacker may use a pretext, the lack of any link, attachment, or email component makes spear phishing technically inapplicable, and vishing is the correct voice-specific term.
When this WOULD be correct
Spear phishing would be correct if the question described a targeted email that appears to come from a trusted source (e.g., IT support) and asks the recipient to click a link or provide credentials via a fake login page.
- ✓
Vishing
Why this is correct
Vishing (voice phishing) is a social engineering attack executed over phone calls or Voice over IP (VoIP), where the attacker impersonates a trusted authority—such as IT support, a bank, or a government agency—to manipulate the victim into revealing sensitive data like passwords, PINs, or one-time MFA codes. This scenario explicitly involves a phone call, which directly aligns with the definition of vishing. The attacker leverages the voice channel to establish urgency and bypass email-based security defenses, making vishing the precise classification under CompTIA Security+.
- ✗
Pretexting
Why it's wrong here
Pretexting is the act of creating a fabricated scenario (pretext) to obtain information, and it can be used across different communication channels. While the attacker does use a pretext in this scenario, 'vishing' is the more specific term when the attack occurs via phone. In the context of CompTIA Security+, vishing is the best answer because it directly identifies the medium (voice).
When this WOULD be correct
Pretexting would be correct if the question described an attacker using a fabricated identity or story (e.g., posing as a vendor or auditor) to obtain information via email, in person, or other means, without specifying the communication channel as voice.
- ✗
Tailgating
Why it's wrong here
Tailgating is a physical security attack in which an unauthorized person follows an authorized individual through a secured entrance, doorway, or checkpoint to gain entry without presenting their own credentials. This attack requires in-person presence at a restricted facility and typically exploits the authorized person's courtesy or inattention to access control measures. Because the scenario involves a phone call rather than physical proximity, tailgating cannot occur; the attacker is not physically following anyone, but is conducting a remote social engineering attempt.
When this WOULD be correct
A question describes an attacker physically following an employee through a secured door without using their own badge, exploiting the employee's courtesy to gain access to a building.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓VishingCorrect answer▾
Why this is correct
Vishing (voice phishing) is a social engineering attack executed over phone calls or Voice over IP (VoIP), where the attacker impersonates a trusted authority—such as IT support, a bank, or a government agency—to manipulate the victim into revealing sensitive data like passwords, PINs, or one-time MFA codes. This scenario explicitly involves a phone call, which directly aligns with the definition of vishing. The attacker leverages the voice channel to establish urgency and bypass email-based security defenses, making vishing the precise classification under CompTIA Security+.
✗Spear phishingWrong answer — click to see why▾
Why this is wrong here
Spear phishing is a targeted email attack, not a phone call. The question describes a voice-based attack (phone call), which is vishing, not spear phishing.
★ When this WOULD be the correct answer
Spear phishing would be correct if the question described a targeted email that appears to come from a trusted source (e.g., IT support) and asks the recipient to click a link or provide credentials via a fake login page.
Why candidates choose this
Candidates may confuse spear phishing with vishing because both are targeted attacks that impersonate a trusted entity, but they forget that spear phishing is specifically email-based, not voice-based.
✗PretextingWrong answer — click to see why▾
Why this is wrong here
Pretexting involves fabricating a scenario to obtain information, but the specific attack vector here is voice-based (phone call), making 'vishing' the more precise term. The question explicitly describes a phone call, which is the defining characteristic of vishing.
★ When this WOULD be the correct answer
Pretexting would be correct if the question described an attacker using a fabricated identity or story (e.g., posing as a vendor or auditor) to obtain information via email, in person, or other means, without specifying the communication channel as voice.
Why candidates choose this
Candidates may confuse pretexting with vishing because both involve deception and identity fabrication. They might focus on the 'false identity' aspect (IT support) and overlook that the phone call makes it specifically vishing.
✗TailgatingWrong answer — click to see why▾
Why this is wrong here
Tailgating involves an unauthorized person physically following an authorized individual into a restricted area without proper authentication, not a phone call requesting credentials.
★ When this WOULD be the correct answer
A question describes an attacker physically following an employee through a secured door without using their own badge, exploiting the employee's courtesy to gain access to a building.
Why candidates choose this
Candidates may confuse tailgating with any attack that bypasses security controls, but tailgating specifically refers to physical access, not social engineering over the phone.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Vishing
Vishing is a social engineering attack where criminals use phone calls or voice messages to trick victims into revealing sensitive information.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.