Courseiva
Threats, Vulnerabilities, and MitigationshardMultiple SelectObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A user receives an SMS from 'IT Service Desk' saying their MFA enrollment expires today and includes a shortened link. Five minutes later, the user gets a phone call from the same number asking them to read back the code shown in the authenticator app so the ticket can be closed. Which two attack channels are used in this campaign? Select two.

⚠ Common exam trap

The trap here is that candidates may focus on the phone call as the only attack channel and overlook the initial SMS, or they may confuse smishing with vishing, not recognizing that both channels are used sequentially in a single campaign.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing is used because the first lure arrives by text message.

The initial attack vector is an SMS message containing a shortened link, which is the definition of smishing (SMS phishing). The attacker uses this to create urgency and lure the victim into engaging with the MFA enrollment scam.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Email phishing is used because the attacker is requesting a login action.

    Why it's wrong here

    Phishing is a broad term, but this scenario is specifically about SMS and voice, not email. Since the channel is not email, calling it email phishing would be inaccurate. The attacker may still be phishing generally, but the more precise attack channels are different and more useful for response.

  • Smishing is used because the first lure arrives by text message.

    Why this is correct

    Smishing is phishing delivered through SMS or another text-based mobile messaging channel. The fake IT Service Desk text with a shortened link is a classic example because it attempts to get the user to click a link and interact outside the normal support process.

  • Vishing is used because the follow-up request occurs by phone call.

    Why this is correct

    Vishing uses voice calls to pressure or trick a victim, often by impersonating support staff or an executive. Asking the user to read back an MFA code on the phone is a strong indicator of vishing because it tries to defeat authentication through social manipulation rather than technical compromise.

  • Baiting is used because the attacker offers a free reward or device.

    Why it's wrong here

    Baiting usually involves enticing the victim with something attractive, such as free media, hardware, or a promised benefit. This scenario instead uses a fake service request and a follow-up call. There is no lure of a reward, so baiting is not the best fit.

  • Tailgating is used because the attacker follows someone into a restricted area.

    Why it's wrong here

    Tailgating is a physical social engineering tactic involving unauthorized entry into a secured space. This scenario takes place over SMS and phone, so it does not involve a person following another through a door or into a controlled area. That makes tailgating irrelevant here.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A facilities manager receives an SMS from "FedEx Delivery" saying a shipment for the research lab cannot clear security until the recipient verifies the package by signing in. The message includes the manager's initials and the warehouse code, and the link opens a cloned sign-in page. Which attack is most likely?

hard
  • A.Smishing, because the attacker is using a text message to deliver a targeted credential lure.
  • B.Vishing, because the attacker is pretending to be a delivery service representative.
  • C.Spear phishing, because the message is targeted using the recipient's role and location.
  • D.Baiting, because the message offers a shipment verification reward to encourage action.

Why A: Smishing is a social engineering attack that uses SMS (Short Message Service) to deliver a fraudulent message designed to trick the recipient into revealing sensitive information. In this scenario, the attacker sends a text message impersonating FedEx, includes the manager's initials and warehouse code for personalization, and provides a link to a cloned sign-in page, which is the classic credential-harvesting mechanism of a smishing attack.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.