Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

Several employees report receiving SMS messages that appear to come from the corporate service desk. The text says, 'Your password expires today. Review the notice here,' followed by a shortened link that opens a fake sign-in page on a phone browser. Which type of attack is this?

⚠ Common exam trap

CompTIA often tests the distinction between smishing and spoofing, where candidates mistakenly choose spoofing because the SMS appears to come from the service desk, but the core attack vector is the social engineering via SMS, not just the falsified sender information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing

This is smishing because the attack uses SMS messages to deliver a phishing link that directs recipients to a fake sign-in page, attempting to steal their credentials. Smishing is a form of social engineering that exploits the trust in text messaging and the urgency of a password expiration notice to bypass email security filters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smishing

    Why this is correct

    Smishing is the correct answer because the attack is phishing delivered over SMS/text messaging. The message creates urgency and instructs the recipient to click a link that leads to a fake login page, harvesting credentials. This fits SMiShing exactly: social engineering plus a malicious URL delivered via Short Message Service.

  • Pretexting

    Why it's wrong here

    Pretexting is incorrect because it refers to a fabricated story or impersonation designed to gain a victim's trust, often over multiple interactions, rather than a one-shot SMS with a credential-harvesting link. While a smishing message may use a pretext, the defining technical characteristic here is the SMS channel and the malicious link, not the narrative itself. The correct label for this specific delivery method is smishing.

  • Tailgating

    Why it's wrong here

    Tailgating is a physical security control failure where an unauthorized person follows an authorized individual through a secured door or gate, often relying on the badge holder's courtesy. That scenario has nothing to do with SMS messages, fake login pages, or credential theft. Since the reported incident is purely digital and arrives as a text message, this option is clearly wrong.

  • Spoofing

    Why it's wrong here

    Spoofing involves falsifying a source identity such as a phone number, email address, or IP address to make a message appear legitimate. An attacker might spoof the sender ID of the SMS, but the attack itself is not fundamentally about source impersonation—it is about tricking the user into submitting credentials via a phishing link. Therefore, spoofing is only a possible component or enabler, not the best overall classification for a text-based phishing attempt.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.