Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

An employee receives a text message saying their payroll account is locked and asks them to tap a link and enter a one-time passcode. What type of attack is this?

⚠ Common exam trap

Many candidates confuse smishing with generic phishing because both involve a link and credential theft, but the exam specifically tests the delivery method (SMS vs. email) as the distinguishing factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing

Smishing (SMS phishing) is the correct classification because the attack vector is a text message (SMS) that lures the recipient into tapping a link and entering a one-time passcode. Unlike generic phishing which uses email, smishing specifically exploits SMS trust and the limited screen real estate of mobile devices to bypass security awareness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing is a broad category of social engineering delivered electronically, but it is most commonly associated with email-based attacks that lure victims to spoofed websites or credential-harvesting forms. Although the scam described is technically a phishing variant, the term doesn't specify the SMS delivery vector; security professionals call that specific subtype smishing. Selecting only 'phishing' would be less precise because the question emphasizes the text-message channel.

  • Smishing

    Why this is correct

    Smishing is phishing delivered by SMS or another text messaging service. The attacker uses urgency and a fake account-lock message to trick the user into clicking a malicious link and giving away a one-time code.

  • Vishing

    Why it's wrong here

    Vishing, or voice phishing, uses phone calls or voicemail rather than text messages—attackers may spoof caller ID or use interactive voice response systems to trick victims into revealing sensitive data. Since the employee's first contact is a text message, no voice channel is involved, so vishing doesn't match the scenario. The distinction matters in incident reports because the mitigation and blocking mechanisms for voice attacks differ from those for SMS attacks.

  • Baiting

    Why it's wrong here

    Baiting works by dangling a desirable reward—such as free music downloads, promotional prizes, or a seemingly abandoned USB flash drive—to convince victims to take an action that installs malware or exposes credentials. The text message uses scarcity and fear (a locked payroll account) instead of appealing to greed or curiosity, so it isn't baiting. Baiting also often requires some physical or voluntary engagement, whereas this attack directly pushes a malicious link via SMS.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.