Social Engineering Authority Exploitation in SY0-601
An organization recently experienced the following social engineering attacks that introduced malware into the network: • In the first attack, the sender impersonated a staff member in the legal department and sent an email stating that the employee needed to click a link to sign an NDA in order to remain employed. The link provided was to a malicious website. • In the second attack, the sender impersonated the director of finance and instructed the accounts payable department to pay an outstanding invoice. The attached invoice contained malware. Which of the following is the most likely reason these attacks were successful?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept tested is how attackers leverage perceived authority to bypass user skepticism and compel immediate action without verification.
This question analyzes two social engineering attacks where impersonation of high-ranking staff led to malware introduction, highlighting the psychological principle of authority.
Candidates often select A (spam filters) because they assume technical controls failed, ignoring that the primary vector for success was human psychology rather than filter evasion.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Both scenarios rely on the psychological trigger of authority. In the first case, the legal department's involvement creates an obligation to comply with employment requirements. In the second, the finance director’s instruction triggers respect for hierarchy and urgency in accounts payable. This exploitation of authority makes employees feel obligated to act quickly, bypassing normal security checks.Why the Other Options Are Wrong
Option A is incorrect because while passing spam filters is a necessary condition for delivery, it does not explain why users clicked or opened attachments; technical filtering failure is not the primary reason for the success of the social engineering aspect. Option B is vague and incorrect because malware concealment is a technical tactic, not the psychological lever used here. Option D is incorrect as there is no evidence provided that dumpster diving was used; these attacks likely used publicly available organizational charts or simple phishing lists.Community Comment Notes
The community strongly agrees on C, noting that both scenarios involve impersonating individuals in positions of power to create a sense of obligation. As one commenter noted, "These both deal with authority," emphasizing the common thread between the legal and finance impersonations.Exam Strategy
When analyzing social engineering questions, identify the psychological trigger (urgency, authority, fear, scarcity). If the attacker impersonates a boss or official entity, look for 'authority' or 'hierarchy' as the correct answer, regardless of technical details like spam filters.
Frequently Asked Questions
Why isn't spam filter failure the main reason?
Spam filters are technical controls. The question asks why the attacks were successful in deceiving users, which is a psychological issue of authority, not just a technical bypass.
How do I distinguish authority from urgency?
Authority involves impersonating someone with power or expertise (e.g., Director, Legal). Urgency involves time pressure (e.g., 'act now or lose access'). These often overlap, but the prompt emphasizes the role of the sender.