SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Exhibit
Help desk call transcript Caller: "Hi, this is Morgan from the executive assistant team. The CFO is in a meeting and needs a transfer completed in the next 15 minutes. I am sending the approval right now. Please confirm the wire amount and account details over the phone so I can finish the request."
Based on the exhibit, what type of social engineering attack is the caller using?
⚠ Common exam trap
Many exam-takers confuse the mention of 'asking for money' with ransomware, but ransomware is a technical malware attack, not a social engineering phone call, and the question explicitly describes a phone-based interaction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing, because the attacker is using a phone call to pressure the target.
The caller is using a phone call to impersonate a trusted figure (the CEO) and create urgency to pressure the target into violating security policy. This matches the definition of vishing (voice phishing), which relies on social engineering over voice channels to extract sensitive information or actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Vishing, because the attacker is using a phone call to pressure the target.
Why this is correct
Vishing is a form of phishing that occurs over voice calls, where the attacker exploits authority, urgency, and intimidation to manipulate the target into disclosing sensitive information, such as financial credentials or personally identifiable information. The phone call in the exhibit creates a real-time, interactive channel that heightens pressure and reduces the target's opportunity to verify the request, which are hallmark characteristics of vishing.
- ✗
Ransomware, because the caller is asking for money.
Why it's wrong here
Ransomware is a category of malware that infects a system and encrypts the victim's files or locks the device, with the attacker demanding a cryptocurrency payment to restore access. The scenario described involves no malicious software, no encryption, and no disruption of digital assets; the request for money is purely a social engineering fraud rather than a technical attack, so the answer is wrong.
- ✗
SQL injection, because the caller is asking for account details.
Why it's wrong here
SQL injection is a web application vulnerability that allows an attacker to send crafted SQL queries through input fields, thereby manipulating a back-end database to retrieve, modify, or delete data. It requires an application with a database and occurs solely in the digital domain, making it entirely distinct from a telephone-based social engineering attempt where the attacker relies on human persuasion rather than code or database interaction.
- ✗
Tailgating, because the attacker mentions an executive assistant.
Why it's wrong here
Tailgating is a physical security breach in which an unauthorized individual follows an authorized person into a restricted area, often by taking advantage of the authorized person's politeness or distraction. While mentioning an executive assistant might serve as a pretext to seem legitimate, the attack in the exhibit is conducted over the phone, not by physically trailing someone through an access-controlled door, so it clearly does not align with tailgating.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.