SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
An attacker calls the service desk claiming to be a traveling contractor whose phone was stolen. They know the contractor's manager name and ask for an MFA reset to a new number 'just for today.' Which control would best reduce the success of this attack?
⚠ Common exam trap
Many candidates think providing a manager's name and employee ID is sufficient proof of identity, but the exam tests that these are easily obtained via reconnaissance and do not constitute multi-factor authentication or out-of-band verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a callback to a previously verified number and ticket approval before reset.
It introduces two verification factors that directly counter the social engineering vector: a callback to a previously verified number ensures the requestor is reachable at a known trusted contact point, and ticket approval creates an audit trail and requires secondary authorization. This combination prevents an attacker from simply claiming an identity and requesting a change without independent confirmation, which is the core weakness the attacker exploits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trust any caller who can provide a manager's name and employee ID.
Why it's wrong here
Trusting a caller solely on a manager’s name and employee ID fails because the attacker has already demonstrated knowledge of the manager’s name, making this a social-engineering credential that does not verify the caller’s identity against a pre-registered device or out-of-band channel. This option is tempting because in a low-risk context, such as resetting a forgotten password for a known internal user, providing a manager’s name and employee ID is often sufficient for identity verification. However, the scenario requires a control that resists an attacker who has obtained that information, such as requiring a biometric match or a callback to a pre-stored number.
- ✓
Require a callback to a previously verified number and ticket approval before reset.
Why this is correct
A callback to a known-good number, combined with ticket validation and approval workflow, forces the request to be verified through independent channels. This defeats the attacker’s ability to rely on stolen or guessed details during the call. It is a practical anti-pretexting control because it reduces trust in information provided by the caller alone.
- ✗
Remove MFA so users are less likely to get locked out while traveling.
Why it's wrong here
Removing MFA eliminates the second authentication factor entirely, which directly contradicts the scenario’s requirement to prevent an attacker from resetting credentials with only social-engineering information. The temptation arises because MFA resets can frustrate legitimate travellers; in a low-risk environment where physical token theft is the primary threat, disabling MFA temporarily might reduce support calls, but here it removes the very control that blocks the attacker’s fraudulent reset request.
- ✗
Use caller ID alone to confirm the person is legitimate.
Why it's wrong here
Caller ID is a caller-provided signaling parameter, not an authenticated identity attribute; it can be trivially spoofed via VoIP, PRI, or carrier manipulation. In a service desk context, relying on it grants the attacker a false sense of legitimacy, as the displayed number does not tie to a verified device or out-of-band challenge. The correct control requires a callback to a pre-registered number, which forces the request through an independent channel the attacker cannot control, rather than trusting a header that can be forged.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Audit trail
An audit trail is a chronological record of events, changes, or activities in a system that provides evidence of who did what, when, and from where.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.