SY0-701 General Security Concepts Practice Question
Exhibit
Phishing awareness summary: - 300 users received a fake help-desk phone call - 17 users disclosed a one-time code - 41 users reported the call - Most failures happened after the caller asked users to "verify" their account Sample call script: "Please read the code from your authenticator app so we can restore access." Training manager note: - Users recognize suspicious emails more often than suspicious phone calls.
Based on the exhibit, which awareness control best addresses the observed failure pattern?
⚠ Common exam trap
Candidates often choose Option A (longer newsletters) because they think more information is always better, but the question specifically tests the ability to match the awareness control to the observed attack vector (vishing), not general security awareness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run targeted vishing exercises and teach a callback verification procedure.
The exhibit shows a pattern where users are falling for phone-based social engineering (vishing), not email or general phishing. Option B directly addresses this by running targeted vishing exercises to simulate the real threat and teaching a callback verification procedure, which is a specific technical control to verify the identity of callers before taking action. This is the most effective awareness control because it trains users to recognize and respond to the exact attack vector observed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace the phone-call simulation with longer monthly policy newsletters.
Why it's wrong here
Long newsletters are passive, one-way communications that do not provide the hands-on, scenario-based practice needed to change behavior in a targeted vishing attack. The exhibit reveals a recurring pattern of employees surrendering one-time codes under phone-based pressure, so the training must include realistic simulations that build the specific skill of recognizing voice pretexting and initiating a callback verification. Reading about vishing, even monthly, rarely translates into different behavior during an actual call, especially when the attacker creates urgency and authority.
- ✓
Run targeted vishing exercises and teach a callback verification procedure.
Why this is correct
This is the best fit because the failures occurred during a phone-based social engineering attack that asked for one-time codes. Targeted vishing drills train users to recognize voice-based pressure tactics, and a callback verification procedure gives them a safe way to confirm legitimacy without relying on the caller. That directly addresses the observed failure pattern.
- ✗
Disable MFA so users are not asked for one-time codes.
Why it's wrong here
Disabling MFA removes the requirement for one-time codes, but the observed failure pattern involves users being blocked by conditional access policies that require a compliant device or trusted location—MFA is not the blocking factor. This option is tempting because MFA fatigue attacks often stem from excessive code prompts, so removing MFA would reduce user friction in a scenario where repeated code requests were the sole cause of failure.
- ✗
Tell users to ignore all requests from anyone outside the company.
Why it's wrong here
Instructing users to ignore all external requests is operationally unrealistic and technically insufficient because attackers can spoof caller IDs to look like internal numbers or use business contexts that employees cannot simply dismiss. A blanket ignore rule disrupts legitimate vendor, partner, and customer interactions, and it does not provide a safe behavioral alternative—so users may instead try to handle calls on their own without verification. The exhibit requires a procedure like hanging up and calling back a known number, which both enables legitimate contact and neutralizes the vishing attempt.
Go deeper
Related to this question
Learn chapter
Access Control Models (DAC, MAC, RBAC)
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Procedure
A documented set of step-by-step instructions for performing a specific task or handling a particular situation in an IT environment.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.