SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A worker receives a text message from someone claiming to be the company's HR partner. The message says a benefits portal issue will be fixed only if the worker clicks a link and logs in right away. What type of attack is this most likely?
⚠ Common exam trap
CompTIA often tests the distinction between the delivery method (SMS = smishing) and the underlying technique (spoofing), so candidates mistakenly choose 'spoofing only' because they see a faked logo or sender ID, ignoring that the attack is defined by its vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing, because the attack is delivered by text message.
This is smishing because the attack vector is a text message (SMS) that attempts to trick the recipient into clicking a malicious link and providing credentials. Smishing is a form of social engineering that exploits the trust in SMS communications, often impersonating a legitimate entity like HR to create urgency. The goal is credential theft, not technical exploitation of the phone's services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Smishing, because the attack is delivered by text message.
Why this is correct
Smishing is a form of social engineering delivered via SMS or text-messaging platforms, relying on urgency and a trusted sender identity to prompt action. In this scenario, the attacker impersonates HR and asks the worker to log in, which is a classic credential-phishing pattern. The defining characteristic is the text message delivery vector, making smishing the precise attack classification.
- ✗
Watering hole, because the attacker compromised the HR partner's website.
Why it's wrong here
A watering hole attack works by compromising a website or third-party resource that the target population is known to visit, then using that site to deliver malware or redirects. Here, the attacker directly messages the worker on their phone instead of tampering with the HR partner's site, and no web compromise is described. The attack vector is outbound SMS, not a passive web-based infection, so this label does not match.
- ✗
Spoofing only, because the attacker copied the HR logo in the message.
Why it's wrong here
Spoofing appears here because the attacker copied the HR logo, but spoofing is a tactic, not the overall attack category. The message's purpose is to convince the worker to supply login credentials, which is phishing; when delivered by text, it is specifically smishing. Labeling it as merely spoofing would ignore the social-engineering objective and the SMS channel, which are central to the classification.
- ✗
Port scanning, because the attacker wants to find open services on the phone.
Why it's wrong here
Port scanning is a technical reconnaissance method that probes a device for open TCP/UDP ports and listening services, typically using tools like Nmap. The fraudulent text message targets the user's trust and does not interact with the phone's network stack. This description is about human manipulation via SMS, not automated network discovery, so port scanning is entirely unrelated.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
Key term
Smishing
Smishing is a social engineering attack that uses deceptive text messages to trick recipients into revealing sensitive information or installing malware.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.