SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
An employee receives a text message from an unknown number pretending to be IT. It includes a shortened URL for "urgent MFA re-enrollment" and says the account will be locked in 15 minutes. What is the best response?
⚠ Common exam trap
Candidates often choose Option A because the message appears urgent and the page looks legitimate, overlooking that attackers can perfectly clone authentication portals and that shortened URLs are a common obfuscation technique in phishing campaigns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the message through the official security channel and verify the request using known IT contact information.
It follows the principle of verifying unsolicited requests through trusted channels, which is a key defense against social engineering and phishing attacks. The message exhibits classic phishing indicators: an unknown sender, a shortened URL (which can mask the true destination), a false sense of urgency, and a request for MFA re-enrollment—a common pretext to harvest credentials or MFA tokens. Reporting through the official security channel ensures the incident is logged and investigated, while verifying with known IT contact information prevents falling for a spoofed or compromised source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open the link and enter the requested information if the page looks legitimate.
Why it's wrong here
Even a visually identical page can be a credential-harvesting site, since attackers routinely copy corporate login layouts and may serve pages through transparent reverse proxies that capture both username/password and session tokens. A legitimate-looking URL or SSL certificate does not authenticate the message sender, and entering the requested information would directly expose the account to an unknown party. Therefore, the safest action is to ignore the link entirely and use an official reporting or verification path.
- ✓
Report the message through the official security channel and verify the request using known IT contact information.
Why this is correct
The safest response is to avoid the link and use an established internal reporting or verification process. This prevents credential theft and helps security track suspicious messages quickly. Verifying through a known contact method, not the message itself, protects the user from smishing and MFA baiting.
- ✗
Forward the text to coworkers so they can check whether they received the same message.
Why it's wrong here
Forwarding the text to coworkers amplifies the attack by spreading a potentially malicious URL or phone number to additional targets, enabling lateral propagation of the smishing campaign. It also provides no identity verification, because neither the original sender nor the coworkers' responses can establish the authenticity of the unknown number. Instead, the message should be reported to the security team so they can analyze the payload and block the hostile infrastructure.
- ✗
Reply to the text asking for a company badge number before proceeding.
Why it's wrong here
Replying to the SMS with a request for a badge number does not create a trusted verification loop—the attacker controls the conversation and can simply fabricate a badge number or escalate the pretext. It also signals to the attacker that the phone number is active and monitored, increasing the likelihood of targeted follow-up phishing or vishing. Genuine verification must occur through separate, known corporate contact methods such as a validated ticketing system or a phone number from the official directory.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.