Courseiva
General Security ConceptshardMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

Exhibit

Phishing awareness summary:
- 300 users received a fake help-desk phone call
- 17 users disclosed a one-time code
- 41 users reported the call
- Most failures happened after the caller asked users to "verify" their account
Sample call script:
"Please read the code from your authenticator app so we can restore access."
Training manager note:
- Users recognize suspicious emails more often than suspicious phone calls.

Based on the exhibit, which awareness control best addresses the observed failure pattern?

⚠ Common exam trap

Candidates often choose Option A (longer newsletters) because they think more information is always better, but the question specifically tests the ability to match the awareness control to the observed attack vector (vishing), not general security awareness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Run targeted vishing exercises and teach a callback verification procedure.

The exhibit shows a pattern where users are falling for phone-based social engineering (vishing), not email or general phishing. Option B directly addresses this by running targeted vishing exercises to simulate the real threat and teaching a callback verification procedure, which is a specific technical control to verify the identity of callers before taking action. This is the most effective awareness control because it trains users to recognize and respond to the exact attack vector observed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Replace the phone-call simulation with longer monthly policy newsletters.

    Why it's wrong here

    Long newsletters are passive, one-way communications that do not provide the hands-on, scenario-based practice needed to change behavior in a targeted vishing attack. The exhibit reveals a recurring pattern of employees surrendering one-time codes under phone-based pressure, so the training must include realistic simulations that build the specific skill of recognizing voice pretexting and initiating a callback verification. Reading about vishing, even monthly, rarely translates into different behavior during an actual call, especially when the attacker creates urgency and authority.

  • Run targeted vishing exercises and teach a callback verification procedure.

    Why this is correct

    This is the best fit because the failures occurred during a phone-based social engineering attack that asked for one-time codes. Targeted vishing drills train users to recognize voice-based pressure tactics, and a callback verification procedure gives them a safe way to confirm legitimacy without relying on the caller. That directly addresses the observed failure pattern.

  • Disable MFA so users are not asked for one-time codes.

    Why it's wrong here

    Disabling MFA removes the requirement for one-time codes, but the observed failure pattern involves users being blocked by conditional access policies that require a compliant device or trusted location—MFA is not the blocking factor. This option is tempting because MFA fatigue attacks often stem from excessive code prompts, so removing MFA would reduce user friction in a scenario where repeated code requests were the sole cause of failure.

  • Tell users to ignore all requests from anyone outside the company.

    Why it's wrong here

    Instructing users to ignore all external requests is operationally unrealistic and technically insufficient because attackers can spoof caller IDs to look like internal numbers or use business contexts that employees cannot simply dismiss. A blanket ignore rule disrupts legitimate vendor, partner, and customer interactions, and it does not provide a safe behavioral alternative—so users may instead try to handle calls on their own without verification. The exhibit requires a procedure like hanging up and calling back a known number, which both enables legitimate contact and neutralizes the vishing attempt.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.