Courseiva
Threats, Vulnerabilities, and MitigationshardMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

Exhibit

Email header and body excerpt:
From: "IT Helpdesk" <help@corp-support.example>
Reply-To: support@mail-secure-login.com
Subject: URGENT: MFA re-sync required

Body:
"Your mailbox will be suspended in 15 minutes. To complete the repair, reply with the 6-digit code that was just sent to your phone. If you do not respond now, your account will be locked."

Based on the exhibit, what is the BEST response by the employee?

The message appears to come from a trusted internal support team, but the sender details and request do not align with normal procedures.

⚠ Common exam trap

It's easy for candidates to assume the email is legitimate because it appears to come from a trusted internal source, leading them to choose an action that involves direct interaction with the email (like replying or clicking a link) rather than verifying through an independent channel, which is the core principle of social engineering defense.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the request using a known internal help desk number or portal before taking any action.

Verifying the request through a known internal help desk number or portal is the standard security practice to confirm the legitimacy of any unexpected communication, especially when sender details and procedures do not align. This approach mitigates the risk of social engineering attacks, such as phishing or business email compromise (BEC), where attackers impersonate trusted entities to trick employees into revealing sensitive information or performing unauthorized actions. By using an independently verified contact method, the employee ensures they are not falling victim to a fraudulent request that could lead to account compromise or data breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify the request using a known internal help desk number or portal before taking any action.

    Why this is correct

    The employee should verify the request through an independently known help desk number or portal, not through any contact details embedded in the email. This message combines urgency, a mismatched reply-to address, and a request for an MFA code — classic indicators of a phishing or vishing attempt. Calling the official help desk number or logging into the official support portal confirms whether the repair request is legitimate before any sensitive action is taken. This out-of-band verification prevents both credential theft and MFA token compromise.

  • Reply with the six-digit code so the help desk can complete the repair quickly.

    Why it's wrong here

    Replying with the six-digit MFA code defeats the entire purpose of multi-factor authentication, which relies on a secret that only the legitimate user possesses. Once shared, the attacker can replay that code during a simultaneous login attempt or use it to complete a session hijacking attack, effectively granting unauthorized access to the account. The claim that the help desk needs the code for a repair is a social engineering pretext designed to exploit urgency and the user's trust in internal functions. No legitimate help desk will ever ask for a live MFA code, as doing so would compromise the security mechanism it is meant to protect.

  • Open the linked repair page from the email and sign in immediately to avoid suspension.

    Why it's wrong here

    Clicking the linked repair page and signing in immediately is dangerous because the email's suspicious sender details and urgent language strongly indicate a phishing email. The link likely points to a credential-harvesting website designed to look like the legitimate login page, where any username and password entered are captured by the attacker. Moreover, if the page also requests an MFA code, the attacker can use it in real-time to authenticate as the user, completing a reverse proxy attack. Following links in unsolicited emails—especially ones that demand immediate action—bypasses all security training and hands over authentication credentials to a malicious third party.

  • Forward the message to the manager and continue using the account until the suspension occurs.

    Why it's wrong here

    Forwarding the message to the manager and then continuing to use the account until a suspension occurs is not a form of verification and leaves the employee vulnerable to account compromise. The manager is not a substitute for the help desk's official verification channel, and waiting for a suspension that may never happen gives the attacker additional time to exploit the pretext or any information already gathered. The correct protocol is to immediately verify the request's legitimacy by contacting the help desk through a verified number or portal, not to defer responsibility or assume the threat is inactive. This option also fails to recognize that the email itself is the threat, so ongoing use of the account while an attacker is actively targeting it increases the risk of successful credential theft.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An employee receives an email that appears to come from the company's payroll provider. It says payroll documents will be deleted today unless the employee signs in through the included link. What is the best first action?

easy
  • A.Click the link quickly and sign in to avoid losing the documents.
  • B.Report the message and verify the request using a trusted contact method.
  • C.Reply to the sender and ask whether the message is legitimate.
  • D.Forward the email to coworkers so they can watch for the same warning.

Why B: The email exhibits classic signs of a phishing attack—urgency, a threat of data loss, and a link to a fake login page. The best first action is to report the suspicious message to the security team and independently verify the request by contacting the payroll provider through a trusted channel (e.g., a known phone number or a previously bookmarked URL). This prevents credential theft and potential account compromise.

Variation 2. An employee receives an email that appears to come from payroll and asks them to open a link to "confirm direct deposit details". The link goes to a site with a slightly misspelled company name. What should the employee do first?

easy
  • A.Click the link and sign in quickly before the account is locked
  • B.Reply to the email and ask payroll whether the message is real
  • C.Use the company's known payroll portal or help desk contact to verify the request
  • D.Forward the message to co-workers so they can compare it with similar emails

Why C: The safest first step when receiving a suspicious email is to verify its legitimacy through a trusted, independent channel—such as the company's known payroll portal or the help desk. This avoids interacting with the potentially malicious link or sender, which could lead to credential theft or malware installation. The email exhibits classic phishing indicators: a spoofed sender, a request for sensitive action, and a URL with a misspelled domain.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.