Which Social Engineering Techniques Are Used in a Fraudulent Text Message?

An employee receives a text message that appears to have been sent by the payroll department and is asking for credential verification. Which of the following social engineering techniques are being attempted? (Choose two.)

  1. Typosquatting
  2. Phishing
  3. Impersonation Source Reference Answer
  4. Vishing
  5. Smishing Source Reference Answer

Community Votes

CE
100%

100% of anonymous learners picked answer CE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question distinguishes between broad attack categories and specific channel-based techniques, trapping candidates who default to "phishing" without recognizing SMS-specific terminology.

This question tests the ability to identify specific social engineering attack vectors based on communication channels and attacker tactics. The community overwhelmingly agrees that impersonation combined with smishing correctly describes an attacker posing as payroll via SMS to steal credentials.

Candidates frequently select Phishing (B) alongside Smishing (E), overlooking that CompTIA treats "phishing" as strictly email-based in official definitions, making Impersonation (C) the more precise second choice for the psychological tactic used.

Community Discussion (21 comments)

Etc_Shadow28000 👍 15 Selected: CE
In this scenario, where an employee receives a text message appearing to be from the payroll department asking for credential verification, the following social engineering techniques are being attempted: C. Impersonation - The attacker is pretending to be a trusted entity (the payroll department) to gain the employee's trust and obtain their credentials. E. Smishing - Smishing (SMS phishing) involves sending fraudulent text messages to trick individuals into revealing personal information, such as credentials, by clicking on a link or responding to the message.
FennecLola 👍 8 Selected: CE
Vishing = voice Phishing = email Smishing = text
IT_dude_in_training 👍 1 Selected: BE
Although impersonation is indeed a tactic used in the attack (the attacker is impersonating the payroll department), the key focus of the attack is the method used (a fraudulent text message aimed at credential theft) rather than simply the act of pretending to be someone else. That is why the answers phishing (B) and smishing (E) are more precise for this scenario.
JackExam2025 👍 1 Selected: CE
Given that the employee only receives a text message (not a phone call), the correct answers would be: E. Smishing C. Impersonation
oldbutgold 👍 3 Selected: BE
CompTIA's official guide states: "Smishing: A phishing attack that uses SMS text communications as the vector." and "Phishing: "Persuades or tricks the target into interacting with a malicious resource disguised as a trusted one, traditionally using email as the vector." It is not impersonation because the Comptia Official guide specifically associates impersonation with direct engagement and persuasion techniques rather than mass communication tactics like smishing or phishing
Hasss 👍 1 Selected: CE
impersonation and smishing
Cyborg1407 👍 1 Selected: CE
Impersonation is a technique Smishing is a technique while Phishing which is also close is a Form. Impersonation and Smishing are under the category of Phishing
dbrowndiver 👍 1 Selected: CE
Answer C: Pretending to Be Payroll: The text message claims to be from the payroll department, a trusted entity within the company. This impersonation aims to create a sense of urgency and legitimacy, convincing the employee to comply with the request for credential verification. The attacker is leveraging the employee's trust in the payroll department to obtain sensitive information, which is a classic example of impersonation in social engineering. Answer E: The attack occurs through a text message, making it a clear case of smishing. The attacker uses SMS to deliver the deceptive message, which asks for credential verification under the guise of being from a legitimate source. Why it is important, since the message is delivered via text and is attempting to harvest credentials, it aligns perfectly with the definition of smishing.
pedrwc7 👍 6 Selected: CE
A. Typosquatting (Impersonation of legitimate URL) B. Phishing (Emails) C. Impersonation (Acting as someone) D. Vishing (Voice Phishing) E. Smishing (Message Phishing or Text Phishing) F. Misinformation (Providing wrong information or fake information or news)
Markeze 👍 2 Selected: CE
The attacker is likely using a combination of C. Impersonation and E. Smishing to trick the employee into revealing their credentials.
kimitsuki 👍 1 Selected: CE
C.Impersonation and E.Smishing
emputu22 👍 1
the answer is C.Impersonation and E.Smishing
c80f5c5 👍 2
phishing by classic definition is over email. Its a similar idea but going strictly by textbook definition it doesn't apply
f26ddcd 👍 1 Selected: CE
Smishing & Impersonate
The_Body 👍 3
Phishing = email Vishing = voice / phone call Smishing = SMS / Tex messages
shady23 👍 3 Selected: BE
B. PhishingE. Smishing
hasquaati 👍 3 Selected: CE
This one is tricky, because Smishing is a part of Phishing. Its one of those annoying questions that Vendors like to throw at exam takers. Smishing is the most specific and direct answer to this question. Answer is CE.
MAKOhunter33333333 👍 4 Selected: CE
Text messages = smishing Appears to be payroll = impersonation
Jimmy1017 👍 1
CE is correct
siddartha3390 👍 1
i think it is: BD
Yoez 👍 3
Correct Answer: CE

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept

Social engineering relies on psychological manipulation rather than technical exploits. Attackers leverage trust, urgency, and specific communication mediums to extract sensitive data.

Why CE is Correct

Impersonation occurs when an attacker poses as a trusted entity (e.g., the payroll department) to lower the target's guard. Smishing (SMS phishing) specifically denotes phishing attacks delivered via text messages. Together, they accurately map to both the method (text) and the tactic (posing as payroll), aligning with CompTIA's SY0-701 objectives.

Why Other Options Are Incorrect

Typosquatting involves registering domains with slight misspellings to trick users, which is irrelevant here. Phishing is traditionally defined by CompTIA as email-based social engineering; while smishing is a subset, the exam expects precise terminology. Vishing uses voice calls or phone systems, which directly contradicts the text message scenario.

Community Consensus & Exam Nuance

As noted by multiple candidates in the discussion, CompTIA's official study materials explicitly separate phishing (email), vishing (voice), and smishing (SMS). While impersonation is a broader psychological tactic, it pairs perfectly with smishing to cover both dimensions of the attack vector. Selecting "Phishing" often marks a candidate who understands the general concept but misses the exam's preference for channel-specific definitions.

Official Reference

Exam Strategy

When answering social engineering questions, always match the communication medium first (SMS → smishing, voice → vishing, email → phishing) before selecting the psychological tactic. If two answers seem overlapping, choose the one that specifies the attack vector and the one that specifies the social manipulation method to maximize accuracy across SY0-701 scenarios.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide