SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
An employee receives a text message saying their payroll account is locked and asks them to tap a link and enter a one-time passcode. What type of attack is this?
⚠ Common exam trap
Many candidates confuse smishing with generic phishing because both involve a link and credential theft, but the exam specifically tests the delivery method (SMS vs. email) as the distinguishing factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
Smishing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) that lures the recipient into tapping a link and entering a one-time passcode. Unlike generic phishing which uses email, smishing specifically exploits SMS trust and the limited screen real estate of mobile devices to bypass security awareness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a broad category of social engineering delivered electronically, but it is most commonly associated with email-based attacks that lure victims to spoofed websites or credential-harvesting forms. Although the scam described is technically a phishing variant, the term doesn't specify the SMS delivery vector; security professionals call that specific subtype smishing. Selecting only 'phishing' would be less precise because the question emphasizes the text-message channel.
- ✓
Smishing
Why this is correct
Smishing is phishing delivered by SMS or another text messaging service. The attacker uses urgency and a fake account-lock message to trick the user into clicking a malicious link and giving away a one-time code.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, uses phone calls or voicemail rather than text messages—attackers may spoof caller ID or use interactive voice response systems to trick victims into revealing sensitive data. Since the employee's first contact is a text message, no voice channel is involved, so vishing doesn't match the scenario. The distinction matters in incident reports because the mitigation and blocking mechanisms for voice attacks differ from those for SMS attacks.
- ✗
Baiting
Why it's wrong here
Baiting works by dangling a desirable reward—such as free music downloads, promotional prizes, or a seemingly abandoned USB flash drive—to convince victims to take an action that installs malware or exposes credentials. The text message uses scarcity and fear (a locked payroll account) instead of appealing to greed or curiosity, so it isn't baiting. Baiting also often requires some physical or voluntary engagement, whereas this attack directly pushes a malicious link via SMS.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.