SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Exhibit
Email header excerpt: From: "Evan Brooks" <evan.brooks@northstar-invoices.co> To: ap-team@contoso.example Subject: Updated pricing for Project Orion - action needed today Message body: Hi Lena, Per our call last week about Project Orion, please review the revised pricing sheet attached. The customer asked for approval before 3:00 PM so we can keep the launch on schedule. If the file does not open, reply here and I will send a new link.
Based on the exhibit, what type of attack is most likely being used against the accounts payable team?
⚠ Common exam trap
Many exam-takers confuse spear phishing with generic phishing because both involve email, but the key differentiator is the level of personalization—spear phishing uses specific details like the recipient's name and project, while phishing uses generic greetings like 'Dear Customer'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spear phishing, because the email is tailored to a specific team, project, and recipient.
B is correct because spear phishing is a targeted attack where the email is customized for a specific individual or group, using personal details like the recipient's name, team, and project to increase credibility. The exhibit shows the email addresses the recipient by name, references the 'Acme Corp Q3 audit' project, and is sent to the accounts payable team, which matches the tailored nature of spear phishing. This makes it more convincing than generic phishing, as the attacker has researched the target to craft a relevant lure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing, because the message asks recipients to open a file and respond quickly.
Why it's wrong here
Phishing is a broad term, but this message is more targeted than a mass-email campaign. The sender references a specific project, a specific recipient, and a believable business context, which indicates a more focused attack.
- ✓
Spear phishing, because the email is tailored to a specific team, project, and recipient.
Why this is correct
This is spear phishing because the attacker uses personalized details such as the recipient's name, the internal project name, and a plausible business deadline. Those details are meant to increase trust and pressure the victim into taking action. The goal is to trick a specific target or group, not to send an indiscriminate message to everyone.
- ✗
Pretexting, because the sender claims to have spoken with the recipient before.
Why it's wrong here
Pretexting involves inventing a story to obtain information, but the primary clue here is a targeted email with a malicious attachment and business urgency. The attack is better classified by the delivery method and personalization.
- ✗
Baiting, because the attacker offers a useful file related to the project.
Why it's wrong here
Baiting attacks lure victims with a tantalizing offer—such as free music, a gift card, or an unattended USB drive—relying on greed or curiosity to overcome caution. In this scenario, the attached file is not an independent enticement; it is embedded in a personalized, authoritative email that references a specific team and project deadline. The victim is not tempted by a generic reward but deceived by perceived legitimacy and urgency, which are the defining traits of spear phishing, not baiting.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Based on the exhibit, which social engineering attack is most likely?
medium- A.Phishing, because the message is a broad email that tries to trick the recipient.
- ✓ B.Spear phishing, because the email is tailored to a specific employee and business context.
- C.Vishing, because the attacker is using a phone call to pressure the victim.
- D.Baiting, because the attacker is offering a document that the user wants to open.
Why B: Spear phishing involves crafting a message that is personalized to a specific individual or role within an organization, often referencing internal processes or names to increase credibility. In the exhibit, the email is addressed to a specific employee and mentions a legitimate-sounding business context (e.g., an internal document or procedure), which is the hallmark of spear phishing rather than a generic blast.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.