Which Social Engineering Techniques Are Used in a Fraudulent Text Message?
An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)
Community Votes
100% of anonymous learners picked answer CE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question distinguishes between broad attack categories and specific channel-based techniques, trapping candidates who default to "phishing" without recognizing SMS-specific terminology.
This question tests the ability to identify specific social engineering attack vectors based on communication channels and attacker tactics. The community overwhelmingly agrees that impersonation combined with smishing correctly describes an attacker posing as payroll via SMS to steal credentials.
Candidates frequently select Phishing (B) alongside Smishing (E), overlooking that CompTIA treats "phishing" as strictly email-based in official definitions, making Impersonation (C) the more precise second choice for the psychological tactic used.
Community Discussion (21 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept
Social engineering relies on psychological manipulation rather than technical exploits. Attackers leverage trust, urgency, and specific communication mediums to extract sensitive data.
Why CE is Correct
Impersonation occurs when an attacker poses as a trusted entity (e.g., the payroll department) to lower the target's guard. Smishing (SMS phishing) specifically denotes phishing attacks delivered via text messages. Together, they accurately map to both the method (text) and the tactic (posing as payroll), aligning with CompTIA's SY0-701 objectives.
Why Other Options Are Incorrect
Typosquatting involves registering domains with slight misspellings to trick users, which is irrelevant here. Phishing is traditionally defined by CompTIA as email-based social engineering; while smishing is a subset, the exam expects precise terminology. Vishing uses voice calls or phone systems, which directly contradicts the text message scenario.
Community Consensus & Exam Nuance
As noted by multiple candidates in the discussion, CompTIA's official study materials explicitly separate phishing (email), vishing (voice), and smishing (SMS). While impersonation is a broader psychological tactic, it pairs perfectly with smishing to cover both dimensions of the attack vector. Selecting "Phishing" often marks a candidate who understands the general concept but misses the exam's preference for channel-specific definitions.
Official Reference
Exam Strategy
When answering social engineering questions, always match the communication medium first (SMS → smishing, voice → vishing, email → phishing) before selecting the psychological tactic. If two answers seem overlapping, choose the one that specifies the attack vector and the one that specifies the social manipulation method to maximize accuracy across SY0-701 scenarios.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →