Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

An attacker calls the service desk claiming to be a traveling contractor whose phone was stolen. They know the contractor's manager name and ask for an MFA reset to a new number 'just for today.' Which control would best reduce the success of this attack?

⚠ Common exam trap

Many candidates think providing a manager's name and employee ID is sufficient proof of identity, but the exam tests that these are easily obtained via reconnaissance and do not constitute multi-factor authentication or out-of-band verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require a callback to a previously verified number and ticket approval before reset.

It introduces two verification factors that directly counter the social engineering vector: a callback to a previously verified number ensures the requestor is reachable at a known trusted contact point, and ticket approval creates an audit trail and requires secondary authorization. This combination prevents an attacker from simply claiming an identity and requesting a change without independent confirmation, which is the core weakness the attacker exploits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Trust any caller who can provide a manager's name and employee ID.

    Why it's wrong here

    Trusting a caller solely on a manager’s name and employee ID fails because the attacker has already demonstrated knowledge of the manager’s name, making this a social-engineering credential that does not verify the caller’s identity against a pre-registered device or out-of-band channel. This option is tempting because in a low-risk context, such as resetting a forgotten password for a known internal user, providing a manager’s name and employee ID is often sufficient for identity verification. However, the scenario requires a control that resists an attacker who has obtained that information, such as requiring a biometric match or a callback to a pre-stored number.

  • Require a callback to a previously verified number and ticket approval before reset.

    Why this is correct

    A callback to a known-good number, combined with ticket validation and approval workflow, forces the request to be verified through independent channels. This defeats the attacker’s ability to rely on stolen or guessed details during the call. It is a practical anti-pretexting control because it reduces trust in information provided by the caller alone.

  • Remove MFA so users are less likely to get locked out while traveling.

    Why it's wrong here

    Removing MFA eliminates the second authentication factor entirely, which directly contradicts the scenario’s requirement to prevent an attacker from resetting credentials with only social-engineering information. The temptation arises because MFA resets can frustrate legitimate travellers; in a low-risk environment where physical token theft is the primary threat, disabling MFA temporarily might reduce support calls, but here it removes the very control that blocks the attacker’s fraudulent reset request.

  • Use caller ID alone to confirm the person is legitimate.

    Why it's wrong here

    Caller ID is a caller-provided signaling parameter, not an authenticated identity attribute; it can be trivially spoofed via VoIP, PRI, or carrier manipulation. In a service desk context, relying on it grants the attacker a false sense of legitimacy, as the displayed number does not tie to a verified device or out-of-band challenge. The correct control requires a callback to a pre-registered number, which forces the request through an independent channel the attacker cannot control, rather than trusting a header that can be forged.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.