How should an organization respond to a CEO impersonation smishing attack?

Several employees received a fraudulent text message from someone claiming to be the Chief Executive Officer (CEO). The message stated: “I’m in an airport right now with no access to email. I need you to buy gift cards for employee recognition awards. Please send the gift cards to following email address.” Which of the following are the best responses to this situation? (Choose two).

  1. Cancel current employee recognition gift cards.
  2. Add a smishing exercise to the annual company training. Source Reference Answer
  3. Issue a general email warning to the company. Source Reference Answer
  4. Have the CEO change phone numbers.
  5. Conduct a forensic investigation on the CEO’s phone.

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to prioritize human-centric incident response over unnecessary technical remediation when dealing with social engineering, with the common trap being the assumption of device compromise despite zero evidence.

This scenario evaluates incident response priorities for SMS-based social engineering, with the community unanimously agreeing that targeted training exercises and immediate company-wide alerts are the most effective countermeasures.

Candidates frequently select options D or E, incorrectly assuming the CEO’s phone was physically stolen or infected with malware, which leads them to pursue costly forensic investigations instead of addressing the actual vulnerability: untrained personnel.

Community Discussion (14 comments)

Mehsotopes 👍 12 Selected: BC
It is already known that the message is not being sent from the CEO, & awareness of this attack should be known among the company by using the proper training to identify when an attacker is smishing using employee likeness. It is not known if devices are compromised, but if employees are aware of the situation, then that can be figured out as well.
AbdullahMohammad251 👍 6 Selected: BC
A fraudulent message was sent without spoofing the sender's number, indicating the message did not come from a legitimate source and the phone wasn't stolen. Therefore, we don't need to change numbers or conduct a forensic investigation on the CEO's phone. We will first inform the employees about the current smishing attack. Then, adjust the annual Company training to include awareness of and protection against similar smishing attacks.
IT_dude_in_training 👍 1 Selected: BC
B. Add a smishing exercise to the annual company training Smishing is a type of phishing attack via text messages. Incorporating it into annual company training will help employees recognize such fraudulent attempts and improve overall security awareness. C. Issue a general email warning to the company This will quickly alert all employees about the specific phishing attempt and provide guidance on how to handle such situations, reducing the risk of future incidents.
JackExam2025 👍 1 Selected: BC
The best responses are to train employees through a smishing exercise and alert the entire company through an email warning to prevent further attacks.
habbeysax 👍 1 Selected: BC
A fraudulent message was sent without the sender's number being spoofed, confirming it did not originate from a legitimate source and that the phone has not been stolen. Consequently, there is no need to change numbers or conduct a forensic investigation on the CEO's phone. Our immediate action will be to inform employees about the ongoing smishing attack. Additionally, we will update the annual company training to include awareness and prevention of similar smishing attacks.
JRCHENRY 👍 1 Selected: BC
Proper training to identify smishing and Employee awareness.
ProudFather 👍 1 Selected: BC
BC seems to be the most reasonable options. As the company with need to be trained and made aware of such attacks so they do not fall victim to this in the future.
famuza77 👍 3 Selected: B
How not implementing Mobile Device Management is gonna help on the situation? Technical measures are more importante than annual trainings? stop asking GTP for responses and think
dbrowndiver 👍 3 Selected: BC
In this scenario, employees have received a fraudulent text message impersonating the CEO, aiming to trick them into purchasing and sending gift cards. The attack is a classic example of smishing, a type of phishing conducted through SMS Add a smishing exercise to the annual company training-Training employees through realistic exercises will prepare them for recognizing smishing attempts in the future. They will learn how to spot red flags in messages that seem urgent and authoritative but are suspicious in nature. Issue a general email warning to the company-o Alerting the organization helps contain the threat and reduces the chance of employees inadvertently engaging with the scam. It is an immediate response that mitigates risk by stopping the scam in its tracks.
Segunmx 👍 1 Selected: BC
These are the correct answers. General email warnings to the employees and there’s a need for more trainings.
AbdullahMohammad251 👍 2 Selected: BC
A fraudulent message was used, and the sender's number was not spoofed, meaning the message didn't come from a legitimate source. The question didn't mention the phone was stolen either. Therefore, we don't need to change numbers or conduct a forensic investigation on the CEO's phone. First, we will inform the employees about the current smishing attack. Then, we will adjust our annual company training to include protection against smishing attacks.
hasquaati 👍 2 Selected: BC
BC, I eliminated the incorrect questions to this one.
shady23 👍 2 Selected: BC
B. Add a smishing exercise to the annual company training. C. Issue a general email warning to the company.
Yoez 👍 2
Correct Answer: BC

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Correct Answers Explained

B. Add a smishing exercise to the annual company training. Smishing (SMS phishing) exploits urgency and authority to bypass user skepticism. Integrating realistic simulation exercises into mandatory security awareness programs directly addresses the root cause: human vulnerability. As multiple community members noted, proactive training builds long-term resilience and helps employees recognize high-pressure, off-channel requests. C. Issue a general email warning to the company. Immediate communication is critical during an active social engineering campaign. Alerting all staff ensures that anyone who has not yet interacted with the attack can identify the pattern, verify future requests through established out-of-band channels, and report suspicious activity promptly.

Why Other Options Are Incorrect

A. Cancel current employee recognition gift cards. While stopping financial loss is a valid goal, the scenario provides no indication that any cards have already been purchased or redeemed. This is a speculative reactive measure rather than a strategic, scalable response. D. Have the CEO change phone numbers & E. Conduct a forensic investigation on the CEO’s phone. Both options assume the executive’s device or carrier account was compromised. The prompt explicitly describes a fraudulent external message spoofing the CEO’s identity, not a breach of their actual hardware. As several candidates correctly pointed out, without evidence of device theft, SIM-swapping, or malware, forensic analysis or number changes are wasteful and distract from addressing the real threat.

Strategic Takeaway

CompTIA Security+ heavily emphasizes security awareness and incident response prioritization. When faced with social engineering, always evaluate whether the threat targets technology or human behavior. If there is no proof of system compromise, prioritize education, verification procedures, and organizational communication over expensive technical interventions.

Official Reference

Exam Strategy

Always distinguish between spoofing/fraud and actual compromise when reviewing scenario details. If a question lacks indicators of device theft, malware, or data exfiltration, eliminate technical remediation options and prioritize human-centric controls like awareness training, policy updates, and immediate communication.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide