Question 33 of 1,013
SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Exhibit
Help desk voicemail transcript: 'Hi, this is Elena from identity operations. I opened ticket INC-7712 because your MFA app is out of sync. Read me the 6-digit code that just arrived so I can clear the lockout before payroll closes.' Ticketing system: no open ticket INC-7712 exists Caller ID displayed: corporate main line
Based on the exhibit, which social engineering attack is most likely?
⚠ Common exam trap
Candidates often confuse vishing with pretexting, but vishing specifically uses voice communication (phone call or voicemail) as the attack vector, whereas pretexting can occur via any medium and focuses on the fabricated story.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
The exhibit shows a voicemail message instructing the recipient to call a specific phone number to verify account activity. This is a classic vishing (voice phishing) attack, where the attacker uses a phone call or voicemail to trick the victim into providing sensitive information or calling a fraudulent number. Unlike phishing, which uses email or text, vishing relies on voice communication channels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing typically involves deceptive emails or fraudulent websites with malicious links or attachments designed to harvest credentials. This attack occurs entirely over a live phone call, with no email or web content involved, so the more precise classification is vishing—voice phishing—rather than generic phishing.
- ✓
Vishing
Why this is correct
The attacker is using a phone call to impersonate support staff and pressure the user into sharing an MFA code. That is voice-based phishing, or vishing. The fabricated ticket number, urgency around payroll, and caller ID spoofing are classic social engineering clues. The goal is credential or factor theft through a believable phone pretext rather than a malicious link or attachment.
- ✗
Baiting
Why it's wrong here
Baiting relies on luring a victim with an attractive offer, such as a free download, contaminated USB drive, or fake prize, to trigger a specific action like inserting a device or clicking a link. The exhibit shows an attacker impersonating support staff on a call to directly coax an MFA code, not offering any digital or physical bait, so baiting does not apply.
- ✗
Pretexting
Why it's wrong here
Pretexting describes the broader tactic of fabricating a believable story to establish false legitimacy, but it is channel-agnostic—it could happen via email, chat, or in person. The exhibit specifically depicts a phone call with urgent requests and caller ID spoofing, which points to vishing as the precise attack type, even though a pretext is being used.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Based on the exhibit, what type of social engineering attack is the caller using?
easy- ✓ A.Vishing, because the attacker is using a phone call to pressure the target.
- B.Ransomware, because the caller is asking for money.
- C.SQL injection, because the caller is asking for account details.
- D.Tailgating, because the attacker mentions an executive assistant.
Why A: The caller is using a phone call to impersonate a trusted figure (the CEO) and create urgency to pressure the target into violating security policy. This matches the definition of vishing (voice phishing), which relies on social engineering over voice channels to extract sensitive information or actions.
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.