Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

What Is a Smishing Attack?

An employee gets a text message saying their mobile carrier will suspend service unless they tap a link and verify their account details. What type of attack is this?

Quick Answer

The answer is smishing, because the attacker uses SMS text messages as the delivery vector to trick the recipient into clicking a malicious link. This is a form of social engineering that exploits the trust users place in text-based communications from known entities like mobile carriers, often leading to credential theft or malware installation. On the Security+ SY0-701 exam, this scenario tests your ability to distinguish smishing from other social engineering variants like vishing (voice calls) or phishing (email), with the key differentiator being the SMS channel. A common trap is confusing smishing with spear phishing, but remember that smishing specifically relies on text messages sent to mobile devices. Memory tip: think “SMS + phishing = smishing,” where the “S” in SMS reminds you it’s a text-based attack.

⚠ Common exam trap

Watch out — candidates often confuse smishing with vishing because both involve phishing via telecommunications, but the key differentiator is the medium: SMS (text) versus voice call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Smishing, because the attacker is using SMS messages to trick the user

This is smishing because the attacker uses SMS (Short Message Service) as the delivery vector to send a fraudulent message that tricks the recipient into clicking a malicious link. Smishing is a form of social engineering that exploits the trust users place in text-based communications from known entities like mobile carriers, often leading to credential theft or malware installation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Smishing, because the attacker is using SMS messages to trick the user

    Why this is correct

    Smishing is phishing delivered through text messages, often with urgent account or delivery claims.

  • Vishing, because the attacker is using a voice call to pressure the user

    Why it's wrong here

    Vishing uses a phone call or voice channel, not a text message with a link.

  • Baiting, because the attacker is offering a free service upgrade

    Why it's wrong here

    Baiting usually relies on a tempting lure, while this message uses urgency and account fear.

  • Tailgating, because the attacker is trying to enter a building behind someone else

    Why it's wrong here

    Tailgating is a physical access attack and has nothing to do with SMS messages.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A worker receives a text message from someone claiming to be the company's HR partner. The message says a benefits portal issue will be fixed only if the worker clicks a link and logs in right away. What type of attack is this most likely?

easy
  • A.Smishing, because the attack is delivered by text message.
  • B.Watering hole, because the attacker compromised the HR partner's website.
  • C.Spoofing only, because the attacker copied the HR logo in the message.
  • D.Port scanning, because the attacker wants to find open services on the phone.

Why A: This is smishing because the attack vector is a text message (SMS) that attempts to trick the recipient into clicking a malicious link and providing credentials. Smishing is a form of social engineering that exploits the trust in SMS communications, often impersonating a legitimate entity like HR to create urgency. The goal is credential theft, not technical exploitation of the phone's services.

Variation 2. Users in a warehouse report an SMS claiming a missed delivery. The link opens a login page that closely matches the company portal, and several users later receive unauthorized password reset emails. What attack is most likely?

medium
  • A.Smishing, because the malicious lure is delivered through text messaging.
  • B.Vishing, because the attackers are likely trying to get a callback from the victims.
  • C.Spear phishing, because the message appears customized for warehouse employees.
  • D.Baiting, because the fake delivery notice tempts users to click for a reward.

Why A: The attack is smishing because the initial lure is delivered via SMS (Short Message Service), directing victims to a fraudulent login page. This aligns with the definition of smishing, a form of phishing that uses text messages to trick recipients into revealing sensitive information. The subsequent unauthorized password reset emails confirm credential compromise, which is the typical goal of smishing attacks.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.