How should an organization respond to a CEO impersonation smishing attack?
Several employees received a fraudulent text message from someone claiming to be the Chief Executive Officer (CEO). The message stated: “I’m in an airport right now with no access to email. I need you to buy gift cards for employee recognition awards. Please send the gift cards to following email address.” Which of the following are the best responses to this situation? (Choose two).
Community Votes
100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to prioritize human-centric incident response over unnecessary technical remediation when dealing with social engineering, with the common trap being the assumption of device compromise despite zero evidence.
This scenario evaluates incident response priorities for SMS-based social engineering, with the community unanimously agreeing that targeted training exercises and immediate company-wide alerts are the most effective countermeasures.
Candidates frequently select options D or E, incorrectly assuming the CEO’s phone was physically stolen or infected with malware, which leads them to pursue costly forensic investigations instead of addressing the actual vulnerability: untrained personnel.
Community Discussion (14 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Correct Answers Explained
B. Add a smishing exercise to the annual company training. Smishing (SMS phishing) exploits urgency and authority to bypass user skepticism. Integrating realistic simulation exercises into mandatory security awareness programs directly addresses the root cause: human vulnerability. As multiple community members noted, proactive training builds long-term resilience and helps employees recognize high-pressure, off-channel requests. C. Issue a general email warning to the company. Immediate communication is critical during an active social engineering campaign. Alerting all staff ensures that anyone who has not yet interacted with the attack can identify the pattern, verify future requests through established out-of-band channels, and report suspicious activity promptly.Why Other Options Are Incorrect
A. Cancel current employee recognition gift cards. While stopping financial loss is a valid goal, the scenario provides no indication that any cards have already been purchased or redeemed. This is a speculative reactive measure rather than a strategic, scalable response. D. Have the CEO change phone numbers & E. Conduct a forensic investigation on the CEO’s phone. Both options assume the executive’s device or carrier account was compromised. The prompt explicitly describes a fraudulent external message spoofing the CEO’s identity, not a breach of their actual hardware. As several candidates correctly pointed out, without evidence of device theft, SIM-swapping, or malware, forensic analysis or number changes are wasteful and distract from addressing the real threat.Strategic Takeaway
CompTIA Security+ heavily emphasizes security awareness and incident response prioritization. When faced with social engineering, always evaluate whether the threat targets technology or human behavior. If there is no proof of system compromise, prioritize education, verification procedures, and organizational communication over expensive technical interventions.Official Reference
Exam Strategy
Always distinguish between spoofing/fraud and actual compromise when reviewing scenario details. If a question lacks indicators of device theft, malware, or data exfiltration, eliminate technical remediation options and prioritize human-centric controls like awareness training, policy updates, and immediate communication.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →