Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

Finance staff receive an email from the 'CFO' using a lookalike domain. The message requests an urgent gift-card purchase, says the recipient must keep it confidential, and pressures them to skip normal approval steps. What attack is this most likely?

⚠ Common exam trap

It's easy for candidates to confuse BEC with credential stuffing (option D) because both involve email accounts, but BEC relies on social engineering to trick the recipient into taking action, not on stealing credentials to access the CFO's mailbox.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Business email compromise using executive impersonation and urgency.

This scenario describes a business email compromise (BEC) attack where the threat actor impersonates an executive (the CFO) using a lookalike domain to trick a finance employee into making an unauthorized gift-card purchase. The use of urgency, confidentiality, and pressure to bypass normal approval processes are classic BEC social engineering tactics, not technical exploits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Watering-hole attack targeting employees through a compromised website.

    Why it's wrong here

    A watering-hole attack would require the CFO or finance staff to visit a legitimate website that was previously compromised and weaponized with malicious JavaScript or exploit kits. The described incident centers on a direct email message that spoofs a senior executive, not on a trusted site delivering malware. Since there is no indication of website compromise or browser-based exploitation, this classification does not match the scenario.

  • Smishing attempt delivered through a text message to a mobile phone.

    Why it's wrong here

    Smishing is a form of phishing that relies on SMS or text messages sent to a mobile phone, often containing a link or callback number to harvest credentials. The scenario explicitly states the communication arrives by email to finance staff, and even if mobile clients are used, the transport medium is email, not SMS. This distinction is critical because smishing uses telephony identifiers and text-based content, whereas the observed attack uses an email-based lookalike domain.

  • Business email compromise using executive impersonation and urgency.

    Why this is correct

    The attacker is impersonating a senior leader, using a lookalike domain, and pressuring the target to bypass normal controls. That combination is typical of business email compromise and executive impersonation. The request for secrecy and urgency is designed to defeat verification and approval workflows, which makes this attack especially effective in finance-related fraud attempts.

  • Credential stuffing against the CFO's mailbox using previously leaked passwords.

    Why it's wrong here

    Credential stuffing is an automated account takeover technique that leverages lists of leaked username/password pairs to gain unauthorized access to a mailbox. The scenario describes a fraudulent message from an attacker impersonating the CFO, not successful login access to the CFO's account; the attacker may have only spoofed the display name and domain. Although leaked passwords could facilitate a real BEC attack, the indicators here—impersonation, urgency, secrecy—are all consistent with social engineering rather than a brute-force/credential replay attempt.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.