Courseiva
Threats, Vulnerabilities, and MitigationshardMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

An accounts payable specialist receives a reply inside an existing vendor email thread. The message uses the real invoice number, matches the vendor's usual tone, and asks the specialist to change payment instructions to a new bank account before the end of the day. The vendor later confirms its mailbox was compromised. What type of attack is most likely?

⚠ Common exam trap

CompTIA often tests the distinction between spear phishing (a crafted email from a fake sender) and BEC conversation hijacking (using a compromised legitimate account to reply within an existing thread), where candidates mistakenly choose spear phishing because they focus on the targeted nature of the attack rather than the method of compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Business email compromise through conversation hijacking, because the attacker used a compromised mailbox to alter a trusted thread.

This is a business email compromise (BEC) attack specifically using conversation hijacking. The attacker gained access to the vendor's legitimate email account and inserted a fraudulent reply into an existing, trusted email thread, leveraging the compromised mailbox to bypass the specialist's suspicion. This differs from standard spear phishing because the attacker did not craft a new email from a spoofed address but instead hijacked an ongoing, authenticated conversation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Spear phishing, because the attacker targeted one employee with a convincing message.

    Why it's wrong here

    Spear phishing is a targeted email crafted to trick a specific user, often using a spoofed or lookalike sender address, but it does not require taking over a genuine vendor mailbox or continuing an established conversation thread. In this incident, the attacker inserted fraudulent instructions into a real, pre-existing email exchange using a compromised account, which is the hallmark of business email compromise through conversation hijacking. The targeting of one employee is a common BEC trait too, but the delegated trust from the stolen thread is what makes this BEC rather than conventional spear phishing.

  • Business email compromise through conversation hijacking, because the attacker used a compromised mailbox to alter a trusted thread.

    Why this is correct

    This is best described as business email compromise via conversation hijacking. The attacker did not just spoof a sender; they gained access to a real vendor mailbox and inserted fraudulent payment instructions into an existing thread. That makes the message much more believable, often bypassing simple awareness checks. The key clues are the real invoice number, familiar tone, and later confirmation of mailbox compromise.

  • Baiting, because the attacker tried to tempt the user with urgency and financial pressure.

    Why it's wrong here

    Baiting exploits a victim's curiosity or greed by offering something tempting, such as free media, a fake prize, or a USB drive left in a parking lot, and it typically does not involve an existing legitimate business relationship. Although the invoice email creates financial urgency, that pressure is not an 'enticing item' and is characteristic of many social engineering attacks, including BEC. The decisive detail is the attacker's unauthorized use of a compromised vendor mailbox inside a real thread, which has nothing to do with baiting's lure-based mechanism.

  • Vishing, because the attacker is trying to persuade the user to change banking details.

    Why it's wrong here

    Vishing, or voice phishing, requires an attacker to place a phone call and use conversational manipulation to extract sensitive data or persuade the victim to take action, often with caller-ID spoofing to impersonate a known entity. In this scenario, there is no voice component at all; the fraudulent banking change arrives in an email, and it is credible because the attacker controls a compromised vendor mailbox rather than a phone line. The act of asking a user to change banking details is not unique to vishing and can be delivered through any medium, so the channel itself rules out vishing.

Go deeper

Related to this question

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.