Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

An employee receives a text message from an unknown number pretending to be IT. It includes a shortened URL for "urgent MFA re-enrollment" and says the account will be locked in 15 minutes. What is the best response?

⚠ Common exam trap

Candidates often choose Option A because the message appears urgent and the page looks legitimate, overlooking that attackers can perfectly clone authentication portals and that shortened URLs are a common obfuscation technique in phishing campaigns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Report the message through the official security channel and verify the request using known IT contact information.

It follows the principle of verifying unsolicited requests through trusted channels, which is a key defense against social engineering and phishing attacks. The message exhibits classic phishing indicators: an unknown sender, a shortened URL (which can mask the true destination), a false sense of urgency, and a request for MFA re-enrollment—a common pretext to harvest credentials or MFA tokens. Reporting through the official security channel ensures the incident is logged and investigated, while verifying with known IT contact information prevents falling for a spoofed or compromised source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Open the link and enter the requested information if the page looks legitimate.

    Why it's wrong here

    Even a visually identical page can be a credential-harvesting site, since attackers routinely copy corporate login layouts and may serve pages through transparent reverse proxies that capture both username/password and session tokens. A legitimate-looking URL or SSL certificate does not authenticate the message sender, and entering the requested information would directly expose the account to an unknown party. Therefore, the safest action is to ignore the link entirely and use an official reporting or verification path.

  • Report the message through the official security channel and verify the request using known IT contact information.

    Why this is correct

    The safest response is to avoid the link and use an established internal reporting or verification process. This prevents credential theft and helps security track suspicious messages quickly. Verifying through a known contact method, not the message itself, protects the user from smishing and MFA baiting.

  • Forward the text to coworkers so they can check whether they received the same message.

    Why it's wrong here

    Forwarding the text to coworkers amplifies the attack by spreading a potentially malicious URL or phone number to additional targets, enabling lateral propagation of the smishing campaign. It also provides no identity verification, because neither the original sender nor the coworkers' responses can establish the authenticity of the unknown number. Instead, the message should be reported to the security team so they can analyze the payload and block the hostile infrastructure.

  • Reply to the text asking for a company badge number before proceeding.

    Why it's wrong here

    Replying to the SMS with a request for a badge number does not create a trusted verification loop—the attacker controls the conversation and can simply fabricate a badge number or escalate the pretext. It also signals to the attacker that the phone number is active and monitored, increasing the likelihood of targeted follow-up phishing or vishing. Genuine verification must occur through separate, known corporate contact methods such as a validated ticketing system or a phone number from the official directory.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.