SY0-701 Question 66
Single answerVoice callA company's help desk receives a voice call from someone claiming to be the CFO, who says they are traveling and urgently need their MFA reset so they can access payroll before a wire transfer deadline. The caller knows the CFO's name, title, and the last four digits of their employee ID. The help desk technician cannot reach the CFO on their corporate mobile number because it goes straight to voicemail. Which action should the technician take FIRST to best follow security best practices while minimizing the risk of account compromise?
- A
Reset the MFA token immediately because the caller provided identifying details and the request is time-sensitive
- B
Send a password reset link to the CFO's personal email address provided by the caller so the issue can be resolved quickly
- C
Refuse to process the request until the caller is verified through an approved out-of-band method or managerial escalation process
- D
Ask the caller to confirm additional public details, such as department name and office location, before performing the reset
Show answer and explanation
Correct answer: C
Explanation
The best answer is to stop the process and use an approved verification or escalation path before making any authentication changes. In Security+, voice-call attacks are commonly framed as vishing, a form of social engineering that relies on urgency, authority, and familiarity to pressure staff into bypassing procedure. Requests involving MFA resets, password resets, or account recovery are especially sensitive because they can directly enable account takeover.
Best practices from common security operations and identity management guidance emphasize strong identity proofing for recovery actions, use of out-of-band verification through trusted contact methods already on file, and strict adherence to documented help desk procedures. Public or easily obtainable details like job title, employee ID fragments, department, or office location are not sufficient proof of identity. Similarly, using contact information provided by the caller is unsafe because it may direct recovery steps to the attacker.
In a real environment, the technician should follow the organization's account recovery policy, document the event, and, if needed, involve a supervisor or security team. This approach reduces the likelihood of compromise while maintaining an auditable and defensible response to a potentially fraudulent voice call.
- A. Incorrect.
This is incorrect. The scenario strongly indicates a potential vishing attempt: urgency, executive impersonation, and a request to bypass MFA controls. Knowing basic identifying details does not sufficiently prove identity because such information may be publicly available or previously exposed. Immediately resetting MFA would create a high risk of account takeover.
- B. Incorrect.
This is incorrect. Sending a reset link to a personal email address supplied during the call bypasses established identity proofing and recovery procedures. Attackers commonly try to redirect recovery actions to channels they control. This option prioritizes convenience over secure verification and would not align with standard help desk account recovery controls.
- C. Correct.
This is correct. Voice calls are a common social engineering vector, and MFA reset requests are high-risk administrative actions. The technician should pause the request and require verification through a preapproved process, such as a callback to a verified number on file, confirmation through an identity management workflow, in-person validation, or documented managerial/security escalation. This is the best first step because it prevents a likely vishing-based account compromise while still allowing a legitimate urgent request to be handled through proper channels.
- D. Incorrect.
This is incorrect. Additional details such as department and office location are often easy to learn from public sources, internal directories, or prior reconnaissance. Asking for more knowledge-based information may feel like stronger verification, but it is weak against impersonation and does not adequately mitigate the risk of social engineering during a live voice call.