SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
An accounts payable specialist receives a reply inside an existing vendor email thread. The message uses the real invoice number, matches the vendor's usual tone, and asks the specialist to change payment instructions to a new bank account before the end of the day. The vendor later confirms its mailbox was compromised. What type of attack is most likely?
⚠ Common exam trap
CompTIA often tests the distinction between spear phishing (a crafted email from a fake sender) and BEC conversation hijacking (using a compromised legitimate account to reply within an existing thread), where candidates mistakenly choose spear phishing because they focus on the targeted nature of the attack rather than the method of compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business email compromise through conversation hijacking, because the attacker used a compromised mailbox to alter a trusted thread.
This is a business email compromise (BEC) attack specifically using conversation hijacking. The attacker gained access to the vendor's legitimate email account and inserted a fraudulent reply into an existing, trusted email thread, leveraging the compromised mailbox to bypass the specialist's suspicion. This differs from standard spear phishing because the attacker did not craft a new email from a spoofed address but instead hijacked an ongoing, authenticated conversation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spear phishing, because the attacker targeted one employee with a convincing message.
Why it's wrong here
Spear phishing is a targeted email crafted to trick a specific user, often using a spoofed or lookalike sender address, but it does not require taking over a genuine vendor mailbox or continuing an established conversation thread. In this incident, the attacker inserted fraudulent instructions into a real, pre-existing email exchange using a compromised account, which is the hallmark of business email compromise through conversation hijacking. The targeting of one employee is a common BEC trait too, but the delegated trust from the stolen thread is what makes this BEC rather than conventional spear phishing.
- ✓
Business email compromise through conversation hijacking, because the attacker used a compromised mailbox to alter a trusted thread.
Why this is correct
This is best described as business email compromise via conversation hijacking. The attacker did not just spoof a sender; they gained access to a real vendor mailbox and inserted fraudulent payment instructions into an existing thread. That makes the message much more believable, often bypassing simple awareness checks. The key clues are the real invoice number, familiar tone, and later confirmation of mailbox compromise.
- ✗
Baiting, because the attacker tried to tempt the user with urgency and financial pressure.
Why it's wrong here
Baiting exploits a victim's curiosity or greed by offering something tempting, such as free media, a fake prize, or a USB drive left in a parking lot, and it typically does not involve an existing legitimate business relationship. Although the invoice email creates financial urgency, that pressure is not an 'enticing item' and is characteristic of many social engineering attacks, including BEC. The decisive detail is the attacker's unauthorized use of a compromised vendor mailbox inside a real thread, which has nothing to do with baiting's lure-based mechanism.
- ✗
Vishing, because the attacker is trying to persuade the user to change banking details.
Why it's wrong here
Vishing, or voice phishing, requires an attacker to place a phone call and use conversational manipulation to extract sensitive data or persuade the victim to take action, often with caller-ID spoofing to impersonate a known entity. In this scenario, there is no voice component at all; the fraudulent banking change arrives in an email, and it is credible because the attacker controls a compromised vendor mailbox rather than a phone line. The act of asking a user to change banking details is not unique to vishing and can be delivered through any medium, so the channel itself rules out vishing.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Spear phishing
Spear phishing is a targeted cyberattack in which a criminal sends a fraudulent email that appears to come from a trusted source, aiming to trick a specific person or organization into revealing sensitive data or installing malware.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.