Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

An employee receives an email that appears to come from the HR team. It says their payroll account will be suspended unless they click a link and sign in within 30 minutes. What type of attack is this most likely?

⚠ Common exam trap

Many exam-takers confuse phishing with vishing or smishing because all three involve impersonation and urgency, but the specific delivery vector (email vs. SMS vs. voice call) is the key differentiator the exam expects you to identify.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing

This is a classic phishing attack because the threat actor uses a deceptive email message to trick the recipient into clicking a malicious link and providing sensitive credentials. Phishing specifically refers to social engineering attacks delivered via email, often leveraging urgency and impersonation of a trusted entity like HR to bypass the victim's critical thinking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smishing

    Why it's wrong here

    Smishing is a phishing variant delivered exclusively through SMS or text messaging platforms, often using shortened URLs or SMS-specific lures. Because the scenario explicitly involves an email message, the vector does not match smishing's definition. Even if the content were identical, the delivery channel separates smishing from email phishing.

  • Phishing

    Why this is correct

    Phishing uses deceptive messages to trick a user into clicking a link, entering credentials, or taking another unsafe action. This email pretends to be from HR, creates urgency, and tries to push the user into signing in on a fake page.

  • Vishing

    Why it's wrong here

    Vishing, or voice phishing, relies on phone calls or VoIP systems to manipulate the target into disclosing sensitive information or performing actions. The attack described is email-borne, with no indication of a live voice interaction or phone call. Vishing typically involves a caller impersonating an authoritative figure, which is not the case here, making Phishing the correct classification.

  • Pretexting

    Why it's wrong here

    Pretexting is a social engineering technique that builds a fabricated scenario or false identity over a series of interactions to establish legitimacy and extract information. In this incident, the entire attack is a single deceptive email luring the user to a fake sign-in page, with no ongoing staged persona or sustained narrative. While pretexting often accompanies phishing, the primary and most precise classification for an email credential-harvesting attempt is Phishing.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.