Courseiva
Question 33 of 1,013
Threats, Vulnerabilities, and MitigationshardMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

Exhibit

Help desk voicemail transcript:
'Hi, this is Elena from identity operations. I opened ticket INC-7712 because your MFA app is out of sync. Read me the 6-digit code that just arrived so I can clear the lockout before payroll closes.'
Ticketing system: no open ticket INC-7712 exists
Caller ID displayed: corporate main line

Based on the exhibit, which social engineering attack is most likely?

⚠ Common exam trap

Candidates often confuse vishing with pretexting, but vishing specifically uses voice communication (phone call or voicemail) as the attack vector, whereas pretexting can occur via any medium and focuses on the fabricated story.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vishing

The exhibit shows a voicemail message instructing the recipient to call a specific phone number to verify account activity. This is a classic vishing (voice phishing) attack, where the attacker uses a phone call or voicemail to trick the victim into providing sensitive information or calling a fraudulent number. Unlike phishing, which uses email or text, vishing relies on voice communication channels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing typically involves deceptive emails or fraudulent websites with malicious links or attachments designed to harvest credentials. This attack occurs entirely over a live phone call, with no email or web content involved, so the more precise classification is vishing—voice phishing—rather than generic phishing.

  • Vishing

    Why this is correct

    The attacker is using a phone call to impersonate support staff and pressure the user into sharing an MFA code. That is voice-based phishing, or vishing. The fabricated ticket number, urgency around payroll, and caller ID spoofing are classic social engineering clues. The goal is credential or factor theft through a believable phone pretext rather than a malicious link or attachment.

  • Baiting

    Why it's wrong here

    Baiting relies on luring a victim with an attractive offer, such as a free download, contaminated USB drive, or fake prize, to trigger a specific action like inserting a device or clicking a link. The exhibit shows an attacker impersonating support staff on a call to directly coax an MFA code, not offering any digital or physical bait, so baiting does not apply.

  • Pretexting

    Why it's wrong here

    Pretexting describes the broader tactic of fabricating a believable story to establish false legitimacy, but it is channel-agnostic—it could happen via email, chat, or in person. The exhibit specifically depicts a phone call with urgent requests and caller ID spoofing, which points to vishing as the precise attack type, even though a pretext is being used.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, what type of social engineering attack is the caller using?

easy
  • A.Vishing, because the attacker is using a phone call to pressure the target.
  • B.Ransomware, because the caller is asking for money.
  • C.SQL injection, because the caller is asking for account details.
  • D.Tailgating, because the attacker mentions an executive assistant.

Why A: The caller is using a phone call to impersonate a trusted figure (the CEO) and create urgency to pressure the target into violating security policy. This matches the definition of vishing (voice phishing), which relies on social engineering over voice channels to extract sensitive information or actions.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.