Social Engineering Authority Exploitation in SY0-601

Threats and Vulnerabilities
Answer Correct answer: C — Both attacks appealed to authority, which made the end users feel obligated to perform the requested actions.

An organization recently experienced the following social engineering attacks that introduced malware into the network: • In the first attack, the sender impersonated a staff member in the legal department and sent an email stating that the employee needed to click a link to sign an NDA in order to remain employed. The link provided was to a malicious website. • In the second attack, the sender impersonated the director of finance and instructed the accounts payable department to pay an outstanding invoice. The attached invoice contained malware. Which of the following is the most likely reason these attacks were successful?

  1. Both attacks passed the spam filters, which resulted in the end users thinking the emails were legitimate.
  2. Both attacks concealed the delivery of malware, which led end users to trust the emails.
  3. Both attacks appealed to authority, which made the end users feel obligated to perform the requested actions. Correct Answer
  4. Both attacks relied on dumpster diving to obtain a list of valid contacts to receive the malicious emails.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept tested is how attackers leverage perceived authority to bypass user skepticism and compel immediate action without verification.

This question analyzes two social engineering attacks where impersonation of high-ranking staff led to malware introduction, highlighting the psychological principle of authority.

Candidates often select A (spam filters) because they assume technical controls failed, ignoring that the primary vector for success was human psychology rather than filter evasion.

Community Discussion (5 comments)

CircaG 👍 5 Selected: C
C. These both deal with authority.
Nemish71 👍 1 Selected: A
By not A. If they have not received the email a first please nothing will happen. Open to discussion!
shady23 👍 1 Selected: C
C. Both attacks appealed to authority, which made the end users feel obligated to perform the requested actions. In both scenarios, the attackers exploited the psychology of authority to deceive the employees. By impersonating individuals in positions of authority within the organization (legal department staff member and director of finance), the attackers created a sense of urgency and obligation among the employees to comply with the instructions provided in the emails.
MortG7 👍 1
C is correct.
Imjusthere00 👍 1 Selected: C
I would say C as CircaG said they both deal with authority.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Both scenarios rely on the psychological trigger of authority. In the first case, the legal department's involvement creates an obligation to comply with employment requirements. In the second, the finance director’s instruction triggers respect for hierarchy and urgency in accounts payable. This exploitation of authority makes employees feel obligated to act quickly, bypassing normal security checks.

Why the Other Options Are Wrong

Option A is incorrect because while passing spam filters is a necessary condition for delivery, it does not explain why users clicked or opened attachments; technical filtering failure is not the primary reason for the success of the social engineering aspect. Option B is vague and incorrect because malware concealment is a technical tactic, not the psychological lever used here. Option D is incorrect as there is no evidence provided that dumpster diving was used; these attacks likely used publicly available organizational charts or simple phishing lists.

Community Comment Notes

The community strongly agrees on C, noting that both scenarios involve impersonating individuals in positions of power to create a sense of obligation. As one commenter noted, "These both deal with authority," emphasizing the common thread between the legal and finance impersonations.

Exam Strategy

When analyzing social engineering questions, identify the psychological trigger (urgency, authority, fear, scarcity). If the attacker impersonates a boss or official entity, look for 'authority' or 'hierarchy' as the correct answer, regardless of technical details like spam filters.

Frequently Asked Questions

Why isn't spam filter failure the main reason?

Spam filters are technical controls. The question asks why the attacks were successful in deceiving users, which is a psychological issue of authority, not just a technical bypass.

How do I distinguish authority from urgency?

Authority involves impersonating someone with power or expertise (e.g., Director, Legal). Urgency involves time pressure (e.g., 'act now or lose access'). These often overlap, but the prompt emphasizes the role of the sender.

Related Analysis

← Back to SY0-601 Study Guide