SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
An employee receives an email from someone claiming to be from IT. The message says the employee must read back a one-time verification code so their mailbox can be 'repaired.' What social engineering technique is being used?
⚠ Common exam trap
It's easy for candidates to confuse pretexting with phishing, but pretexting specifically relies on a fabricated scenario or identity (the 'pretext') rather than a generic lure like a malicious link or attachment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting, because the attacker is using a fake identity and story to gain trust.
The attacker is using a fabricated identity (IT support) and a false scenario (mailbox repair requiring a verification code) to manipulate the employee into divulging sensitive information. This is the classic definition of pretexting, where the attacker creates a believable pretext to lower the victim's defenses and extract data or access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tailgating, because the attacker is trying to enter a secure area physically.
Why it's wrong here
Tailgating, also known as piggybacking, exploits physical access controls by following an authorized person through a secure doorway without presenting credentials. The described attack is purely digital and relies on psychological manipulation via email to obtain a one-time code, with no physical presence or access-control bypass involved. Tailgating would require the attacker to be at the facility and does not explain the request for a secret code.
- ✓
Pretexting, because the attacker is using a fake identity and story to gain trust.
Why this is correct
Pretexting is a social engineering technique where the attacker fabricates a scenario and adopts a trusted role—here, an IT support agent—to elicit sensitive information. The email invents a believable reason, such as account verification or troubleshooting, to lower the victim's suspicion and prompt disclosure of the one-time code. This relies on establishing false trust and exploiting the victim's willingness to comply with an authority figure, making it distinct from technical attacks.
- ✗
DDoS, because the message is designed to overwhelm the mailbox server.
Why it's wrong here
A distributed denial-of-service (DDoS) attack aims to exhaust a target server's or network's resources by flooding it with traffic from many compromised systems. It is an availability attack, not a confidentiality attack, and does not involve sending a deceptive email or requesting a one-time passcode. The email targets a single user's trust and secrets, whereas DDoS would be directed at the mail server's infrastructure and would not require a response from the victim.
- ✗
Shoulder surfing, because the attacker is watching the screen from nearby.
Why it's wrong here
Shoulder surfing is a direct observation attack where the attacker visually captures sensitive data, such as a one-time code, by looking over the victim's shoulder or using recording devices. This scenario involves an email-based request, so the threat actor never needs to be physically near the victim. Even if the attacker later uses the code, the initial compromise vector is a fabricated communication, not line-of-sight surveillance.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Pretexting
Pretexting is a social engineering attack where the attacker fabricates a believable scenario or false identity to trick a victim into revealing sensitive information or performing an action.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.