SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Several employees receive a text message that says their payroll deposit failed and they must tap a link to verify account details. The link opens a fake login page. What type of attack is this?
⚠ Common exam trap
A common mix-up: candidates confuse 'smishing' with general 'phishing' because they do not differentiate the delivery vector (SMS vs. email), but the SY0-701 exam expects you to identify the specific attack type based on the communication channel used.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing
Smishing is a form of phishing that uses SMS (Short Message Service) text messages as the attack vector. In this scenario, the attacker sends a fraudulent text message claiming a payroll deposit failure and includes a link to a fake login page, which is the classic mechanism of smishing. The attack relies on social engineering via SMS to trick the recipient into revealing sensitive credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is the overarching term for social engineering attacks that use fraudulent messages to trick recipients into disclosing sensitive information or downloading malware, but it traditionally encompasses email, VoIP, and other channels. While the payroll text qualifies as phishing in the broadest sense, the specific delivery via SMS requires the more precise label of smishing, so it is not the best answer. The attack vector's unique characteristics, like limited spam filtering on SMS, make the distinction important for incident response.
- ✓
Smishing
Why this is correct
Smishing is a form of phishing that specifically arrives through SMS/text messaging, exploiting a channel where users are less suspicious and messages are not as heavily filtered as email. In this case, the text about payroll is an attempt to lure employees into clicking a malicious link or providing credentials, which matches smishing's signature of leveraging urgent, work-related topics to prompt immediate action. Because the delivery method is text message, smishing is the exact and correct classification.
- ✗
Pretexting
Why it's wrong here
Pretexting is a social engineering technique where the attacker manufactures a convincing scenario, or pretext, to fabricate trust and extract information, often impersonating a coworker or authority figure. The payroll message may arguably contain a story, but the basis for classifying an attack is typically the delivery method and the direct attempt to steal credentials or install malware, not the narrative alone. Since the message is delivered by text and uses a standard phishing lure, it is more accurately a smishing attack, making pretexting an incorrect, though superficially plausible, choice.
- ✗
Baiting
Why it's wrong here
Baiting relies on piquing a victim's curiosity or greed with an enticing offer, such as free gifts, music downloads, or a dropped USB drive, which the victim must physically access or intentionally engage with. A payroll text does not present a separate lure; it creates a sense of urgency or concern about compensation, rather than appealing to the victim's desire to gain something. Because the attack is a direct request for action via text message without an external object or reward, it does not meet the definition of baiting, and smishing remains the proper answer.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Smishing
Smishing is a social engineering attack that uses deceptive text messages to trick recipients into revealing sensitive information or installing malware.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.