Social Engineering MFA Reset Request: How to Verify Before Acting
A help desk receives an email from an employee asking to urgently reset MFA because they are traveling and locked out. The sender address matches the employee's name but uses a slightly different domain. What is the best action for the help desk agent?
Quick Answer
The correct action is to use a separate, known-good contact method to verify the request before making any change. This is essential because the email’s domain mismatch is a classic red flag for a social engineering MFA reset verification attack, where an attacker impersonates a legitimate user to bypass a critical authentication control. On the Security+ SY0-701 exam, this scenario tests your understanding of out-of-band verification as a defense against phishing and social engineering, often appearing in questions about identity verification procedures. A common trap is to rely solely on the sender’s display name or email content, but the exam emphasizes that MFA resets must never be processed without independent confirmation. Remember the mnemonic: “Verify out-of-band, or lose command.”
⚠ Common exam trap
A common mix-up: candidates assume a matching display name and a plausible story (urgent travel) are sufficient for trust, overlooking the domain mismatch as the primary red flag that demands out-of-band verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a separate, known-good contact method to verify the request before making any change.
The email's domain mismatch is a classic indicator of a phishing or social engineering attempt. The help desk must verify the request through a separate, known-good communication channel (e.g., a phone call to the employee's official number or an in-person verification) before resetting MFA, as MFA reset bypasses a critical authentication control. This aligns with the principle of out-of-band verification to prevent unauthorized account takeover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset MFA immediately because the request appears to come from the employee.
Why it's wrong here
Acting on the email alone could help an attacker bypass authentication using a spoofed or lookalike address.
- ✗
Reply to the email and ask the employee to confirm the request in writing.
Why it's wrong here
Replying through the same suspicious channel does not provide trustworthy verification and may continue the attack.
- ✓
Use a separate, known-good contact method to verify the request before making any change.
Why this is correct
The safest response is to verify the request through a trusted channel that is independent of the suspicious email, such as a known phone number or established ticketing workflow. This helps prevent account takeover through impersonation or domain spoofing. After verification, the help desk can follow normal reset procedures and record the event for accountability. This is a practical anti-social-engineering habit.
- ✗
Forward the message to everyone in IT so another technician can decide what to do.
Why it's wrong here
Broadcasting the message increases exposure and still does not confirm whether the request is legitimate.
Go deeper
Related to this question
Learn chapter
Authentication Methods
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An employee receives a phone call from someone claiming to be IT and asking for a one-time verification code to "fix" the employee's account. What is the best response?
easy- A.Provide the code quickly so the support call can be completed without delay.
- ✓ B.Refuse to share the code and report the call through the company's security process.
- C.Reply to the caller by email with the code and ask them to confirm receipt.
- D.Change the password immediately and then tell the caller the new password.
Why B: It follows the principle of never sharing authentication factors, especially one-time verification codes, with anyone over the phone. This scenario is a classic social engineering attack (vishing) where the attacker attempts to bypass multi-factor authentication (MFA) by tricking the employee into revealing a time-based one-time password (TOTP) or similar code. Reporting the call through the company's security process allows the incident to be investigated and mitigates further risk.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.