SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Which four of the following are common indicators of a phishing attack? (Choose four.)
⚠ Common exam trap
The SY0-701 exam often tests the misconception that technical security features like digital signatures or HTTPS encryption automatically indicate legitimacy, when in fact attackers can obtain valid certificates or bypass signature verification through social engineering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Urgent or threatening language demanding immediate action
These four options are correct because they represent classic hallmarks of phishing attacks. Urgent or threatening language is a social engineering tactic to bypass rational thought. Spoofed sender addresses exploit trust in familiar domains. Unsolicited attachments or links are the primary delivery mechanism for phishing payloads. Grammatical errors and poor formatting often indicate a lack of professional quality control typical of legitimate organizations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Urgent or threatening language demanding immediate action
Why this is correct
Urgency and threatening language are psychological triggers used in phishing to bypass rational evaluation, pressuring the recipient into acting before verifying authenticity. Attackers exploit fear of account suspension, legal action, or financial loss to evoke an immediate response. While legitimate organizations may use urgency for true security alerts, unsolicited messages demanding rapid action without prior context are a hallmark phishing indicator.
- ✓
Spoofed sender email address that mimics a legitimate domain
Why this is correct
A spoofed sender address is a direct manipulation of email header fields, often using domain impersonation like 'rnicrosoft.com' or homoglyph attacks to visually mimic a trusted brand. This exploits the user's trust in the display name rather than the actual SMTP envelope, and can bypass naive filters. Phishing relies on this deception to establish false credibility, making it a strong indicator when combined with other suspicious traits.
- ✓
Unsolicited attachment or link that prompts credential entry
Why this is correct
Unsolicited attachments or links that route to credential-harvesting pages are classic phishing vectors because they provide the vehicle for the actual attack. The attachment may deliver malware, while the URL may lead to a rogue login portal that captures entered credentials. The key indicator is the unsolicited nature and the prompt to enter sensitive data, as legitimate entities rarely request credentials via unsolicited email links.
- ✗
Presence of a digital signature from a trusted certificate authority
Why it's wrong here
A digital signature from a trusted certificate authority is not an indicator of phishing; rather, it is an authenticity and integrity mechanism that verifies the signer's identity and guarantees the message was not altered. Phishing emails almost never carry valid digital signatures from CAs, and their presence generally suggests a legitimate, signed corporate communication. Therefore, seeing a trusted CA signature should decrease suspicion, not serve as a phishing red flag.
- ✓
Grammatical errors and poor formatting in the message body
Why this is correct
Grammatical errors, awkward phrasing, and inconsistent formatting are common because many phishing campaigns originate from non-native speakers or use template-based content that lacks brand-specific polish. Legitimate organizations invest in professional copyediting and consistent HTML styling, so obvious linguistic flaws stand out as anomalies. While not conclusive alone, these textual inconsistencies are frequently cited as observable phishing indicators that should prompt closer inspection.
- ✗
A request for sensitive information via a secure web portal
Why it's wrong here
A request for sensitive information via a secure web portal is actually a security best practice, not a phishing indicator, because legitimate services use HTTPS-encrypted portals for credential submission. Phishing instead directs victims to lookalike domains or embedded forms that do not carry the same trusted portal characteristics. The presence of a secure portal with a valid certificate and recognized URL indicates safe handling of data, so this option is incorrect as a phishing sign.
Go deeper
Related to this question
Learn chapter
Social Engineering Attacks
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Exploit
An exploit is a piece of code, a sequence of commands, or a technique that takes advantage of a vulnerability in a system or software to cause unintended behavior, often for malicious purposes.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.