SY0-701 exam dumps

SY0-701 practice question 61 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 61

Single answerMessage-based: Email , Short Message Service (SMS) , Instant messaging (IM) , Image-based

A company's security team notices an increase in successful account takeovers. In several cases, users received a text message that appeared to come from the company's IT help desk, telling them to click a link to revalidate their VPN account. A few employees also received the same message through a corporate instant messaging platform from compromised coworker accounts. The links led to a fake single sign-on page that captured usernames, passwords, and MFA codes. The company wants to reduce the risk of this type of attack across both SMS and IM with the most effective security control. Which of the following should the company implement first?

  1. A

    Deploy a security awareness program focused on smishing and messaging-based phishing, including verification procedures for help desk requests

  2. B

    Block all external email attachments at the email gateway

  3. C

    Require users to change their passwords every 30 days

  4. D

    Disable image previews in messaging applications

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy a security awareness program specifically addressing smishing and phishing through messaging platforms, combined with verification procedures for help desk or account-related requests. The scenario shows a classic social engineering attack adapted to message-based channels: SMS and instant messaging. Attackers impersonate trusted internal support personnel and direct users to a spoofed authentication portal, capturing credentials and even MFA codes in real time. Since the attack bypasses traditional email-focused defenses, the organization should first strengthen human-layer defenses and establish clear processes such as verifying IT requests through known phone numbers, service desk tickets, or internal portals rather than links in messages. This aligns with widely accepted guidance from CISA on phishing resistance and NIST recommendations for security awareness and verifier impersonation resistance. While additional technical controls such as phishing-resistant MFA, conditional access, mobile threat defense, URL filtering, and IM security monitoring would also help, the question asks for the most effective first control for this specific SMS/IM social engineering problem.

  • A. Correct.

    Correct. This scenario describes smishing and instant-message phishing that trick users into visiting a fraudulent login page and entering credentials and MFA codes. Because the attack is delivered through SMS and IM rather than traditional email, targeted security awareness training and clear verification procedures for IT requests are the most directly effective first control. Users should be trained to avoid clicking links in unsolicited messages, verify requests through trusted channels, and report suspicious messages. Security best practices from organizations such as NIST and CISA emphasize user awareness and out-of-band verification as key defenses against social engineering and phishing across communication channels.

  • B. Incorrect.

    Incorrect. Blocking external email attachments may help reduce email-borne malware risk, but it does not address the primary delivery methods in this scenario: SMS and instant messaging. A candidate might choose this because phishing is often associated with email, but the facts here point to message-based phishing outside the email gateway's control.

  • C. Incorrect.

    Incorrect. More frequent password changes do not meaningfully prevent users from submitting their credentials and MFA codes to a fake site. In modern guidance, forced frequent password rotation without evidence of compromise is generally not considered a strong primary control because it can lead to weaker password practices. The issue here is successful social engineering, not password age.

  • D. Incorrect.

    Incorrect. Disabling image previews may reduce risk from some image-based attacks or malicious content rendering, but the scenario is centered on fraudulent links delivered by SMS and IM and a fake login page harvesting credentials. This option does not directly mitigate the core attack path. Someone might pick it because the topic includes image-based messaging threats, but that is not the main risk described.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam