Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

An employee receives a text message that says, "Your MFA enrollment expired. Tap here now to re-activate access or your account will be locked." What should the employee do first?

⚠ Common exam trap

Test-takers frequently assume MFA is unbreakable and rush to re-enroll, not realizing that phishing kits can intercept MFA tokens in real time via reverse proxy attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the request using a known company contact method and report the text

The message is a classic phishing attempt designed to harvest MFA credentials or session tokens. The employee must first verify the request through a trusted company channel (e.g., calling the IT help desk or checking the official security portal) and then report the text to the security team. This prevents falling for social engineering that could bypass MFA protections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Tap the link and complete the MFA reset immediately

    Why it's wrong here

    Tapping the link in an unsolicited text message is dangerous because it can lead to a credential-harvesting site that mimics the legitimate MFA prompt, capturing both the password and the one-time code. This is a common SMiShing technique that enables real-time relay or replay attacks, potentially allowing the attacker to bypass MFA and gain unauthorized access. The urgency of an 'act immediately' request is a social engineering trigger designed to bypass the user's critical thinking, so the correct response is to ignore the link and verify through a trusted channel.

  • Verify the request using a known company contact method and report the text

    Why this is correct

    This is the best first step because the employee should not trust a security-related request delivered through an unexpected text message. Using a known internal help desk number, portal, or security reporting process confirms whether the request is legitimate. It also helps the organization investigate the suspicious message quickly.

  • Forward the text to coworkers so they can watch for it too

    Why it's wrong here

    Forwarding the text to coworkers amplifies the threat by spreading a suspected malicious link to additional recipients, increasing the likelihood that someone will click it and compromise their credentials. This also converts the employee from a victim into an unwitting distributor of the phishing campaign, which can cause a wider organizational breach. Instead, the message should be reported to the security or IT help desk through the approved internal process so that the incident response team can block the domain, analyze the payload, and alert others without exposing them to the link.

  • Reply to the sender and ask for more details

    Why it's wrong here

    Replying to the sender is counterproductive because it confirms that the phone number is active and monitored, which likely adds the target to a list for future phishing, vishing, or SMS spam campaigns. It also provides no verification of the request's legitimacy, as an attacker can simply fabricate credentials or escalate the social engineering. The only safe way to handle a suspicious MFA text is to ignore the reply option and independently confirm the request through a known company contact method, such as the help desk number on the corporate intranet, before taking any action.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.