Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A worker receives a text message from someone claiming to be the company's HR partner. The message says a benefits portal issue will be fixed only if the worker clicks a link and logs in right away. What type of attack is this most likely?

⚠ Common exam trap

CompTIA often tests the distinction between the delivery method (SMS = smishing) and the underlying technique (spoofing), so candidates mistakenly choose 'spoofing only' because they see a faked logo or sender ID, ignoring that the attack is defined by its vector.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing, because the attack is delivered by text message.

This is smishing because the attack vector is a text message (SMS) that attempts to trick the recipient into clicking a malicious link and providing credentials. Smishing is a form of social engineering that exploits the trust in SMS communications, often impersonating a legitimate entity like HR to create urgency. The goal is credential theft, not technical exploitation of the phone's services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smishing, because the attack is delivered by text message.

    Why this is correct

    Smishing is a form of social engineering delivered via SMS or text-messaging platforms, relying on urgency and a trusted sender identity to prompt action. In this scenario, the attacker impersonates HR and asks the worker to log in, which is a classic credential-phishing pattern. The defining characteristic is the text message delivery vector, making smishing the precise attack classification.

  • Watering hole, because the attacker compromised the HR partner's website.

    Why it's wrong here

    A watering hole attack works by compromising a website or third-party resource that the target population is known to visit, then using that site to deliver malware or redirects. Here, the attacker directly messages the worker on their phone instead of tampering with the HR partner's site, and no web compromise is described. The attack vector is outbound SMS, not a passive web-based infection, so this label does not match.

  • Spoofing only, because the attacker copied the HR logo in the message.

    Why it's wrong here

    Spoofing appears here because the attacker copied the HR logo, but spoofing is a tactic, not the overall attack category. The message's purpose is to convince the worker to supply login credentials, which is phishing; when delivered by text, it is specifically smishing. Labeling it as merely spoofing would ignore the social-engineering objective and the SMS channel, which are central to the classification.

  • Port scanning, because the attacker wants to find open services on the phone.

    Why it's wrong here

    Port scanning is a technical reconnaissance method that probes a device for open TCP/UDP ports and listening services, typically using tools like Nmap. The fraudulent text message targets the user's trust and does not interact with the phone's network stack. This description is about human manipulation via SMS, not automated network discovery, so port scanning is entirely unrelated.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.