SY0-701 exam dumps

SY0-701 practice question 62 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 62

Select 2Message-based: Email , Short Message Service (SMS) , Instant messaging (IM) , Image-based

A company's security team is investigating a rise in account takeovers. Several employees reported receiving text messages that appeared to come from the IT help desk, asking them to click a link to "revalidate" their VPN access. Another employee received a QR code image in a group chat that supposedly linked to a new payroll portal. The SOC wants to reduce the risk from these message-based attacks without blocking legitimate business communication. Which TWO controls would best address this threat?

  1. A

    Deploy a mobile threat defense/MDM solution that can inspect and restrict access to malicious links from SMS and messaging apps on managed devices

  2. B

    Implement security awareness training that specifically covers smishing, QR-code phishing (quishing), and verification of links sent through chat platforms

  3. C

    Disable all corporate email accounts on mobile devices so users cannot access messages outside the office

  4. D

    Replace HTTPS inspection on the web proxy with DNS sinkholing only, since SMS attacks do not use web content

  5. E

    Require users to authenticate to internal portals with phishing-resistant MFA such as FIDO2 security keys

Show answer and explanation

Correct answers: B, E

Explanation

The best answers are security awareness training focused on message-based phishing techniques and phishing-resistant MFA. The scenario involves smishing via SMS, malicious links delivered through instant messaging, and image-based QR-code phishing. In Security+ terms, these are social engineering attacks using message-based delivery methods. Training helps users identify and report suspicious requests, while phishing-resistant MFA reduces the chance that compromised credentials can be used successfully.

This approach aligns with common best practices from organizations such as CISA and NIST. CISA has specifically warned about smishing and QR-code phishing campaigns, emphasizing user verification and skepticism of unsolicited messages. NIST SP 800-63 and related guidance support phishing-resistant authenticators, such as FIDO2/WebAuthn, as stronger protection against credential phishing than traditional OTP-based methods. While mobile device management, web filtering, and DNS protections can be valuable layered defenses, they are not as directly effective as the selected controls for reducing account takeover from these message-based attacks without broadly disrupting legitimate communication.

  • A. Incorrect.

    This is a useful supporting control in some environments, especially for managed mobile devices, because MDM/mobile threat defense can enforce safe browsing policies, detect risky apps, and help protect users on corporate devices. However, it is not the best answer here because the scenario includes multiple message channels and the question asks for the TWO controls that most effectively reduce account-takeover risk without broadly disrupting communication. It also may not cover personal devices or all chat/image-based vectors consistently.

  • B. Correct.

    Correct. Targeted security awareness training is one of the most effective controls for message-based social engineering attacks such as smishing, malicious instant messages, and QR-code phishing. Users need to recognize suspicious requests, avoid clicking embedded links or scanning unsolicited QR codes, and verify requests through a trusted channel. This directly addresses the attack method described in the scenario.

  • C. Incorrect.

    Incorrect. Disabling corporate email on mobile devices would be overly disruptive and does not address the primary attack paths in the scenario, which are SMS and instant messaging with image-based QR codes. It also harms legitimate business communication, which the question explicitly says should not be blocked unnecessarily.

  • D. Incorrect.

    Incorrect. DNS sinkholing can help block known malicious domains, but replacing HTTPS inspection with DNS controls only would reduce visibility into web traffic and does not make sense as a primary response to message-based phishing. The misconception is that because the lure arrives by SMS or chat, web-layer protections are less important; in reality, users are still being driven to malicious websites.

  • E. Correct.

    Correct. Phishing-resistant MFA significantly reduces the likelihood that stolen credentials from smishing or chat-based phishing can be used for account takeover. FIDO2/WebAuthn security keys are designed to resist replay and adversary-in-the-middle phishing techniques better than SMS or app-based one-time codes. This control addresses the impact of credential theft even if a user clicks a malicious link.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam