SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Users in a warehouse report an SMS claiming a missed delivery. The link opens a login page that closely matches the company portal, and several users later receive unauthorized password reset emails. What attack is most likely?
⚠ Common exam trap
CompTIA often tests the distinction between attack vectors (SMS vs. email vs. voice) rather than the content of the lure, so candidates may confuse smishing with spear phishing if they focus on the customized delivery notice instead of the delivery method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Smishing, because the malicious lure is delivered through text messaging.
The attack is smishing because the initial lure is delivered via SMS (Short Message Service), directing victims to a fraudulent login page. This aligns with the definition of smishing, a form of phishing that uses text messages to trick recipients into revealing sensitive information. The subsequent unauthorized password reset emails confirm credential compromise, which is the typical goal of smishing attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Smishing, because the malicious lure is delivered through text messaging.
Why this is correct
Smishing is specifically an SMS-based phishing attack. The deceptive text message claiming a missed delivery and the accompanying fake portal are classic smishing indicators, as the attack vector is the Short Message Service on mobile devices. The message creates urgency to lure users into clicking a malicious link, which is the core mechanism of smishing.
- ✗
Vishing, because the attackers are likely trying to get a callback from the victims.
Why it's wrong here
Vishing, or voice phishing, is executed through phone calls, often using VoIP to spoof caller ID and impersonate a legitimate entity. While attackers might hope for a callback, the initial lure here is a text message containing a link, not a phone call. Since no voice interaction occurs, and the delivery method is SMS, classifying this as vishing would be incorrect.
- ✗
Spear phishing, because the message appears customized for warehouse employees.
Why it's wrong here
Spear phishing is a highly targeted form of phishing that uses personalized context, such as the victim's name, role, or recent activity, to increase credibility. In this scenario, the generic missed-delivery message is likely sent to many users and does not contain unique personalization for each warehouse employee. The defining characteristic is the SMS channel, which makes smishing the more precise classification despite any superficial targeting.
- ✗
Baiting, because the fake delivery notice tempts users to click for a reward.
Why it's wrong here
Baiting is a social engineering technique that offers a tangible or virtual reward—like a free music download, a USB drive, or a prize—to entice victims into performing an action. The fake delivery notice does not promise a reward; instead, it induces anxiety over a missed package to provoke a click. Baiting typically relies on curiosity or greed, whereas this attack leverages fear and impersonation via SMS.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Smishing
Smishing is a social engineering attack that uses deceptive text messages to trick recipients into revealing sensitive information or installing malware.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.