Identifying Social Engineering Tactics in Security Awareness Scenarios
After a security awareness training session, a user called the IT help desk and reported a suspicious call. The suspicious caller stated that the Chief Financial Officer wanted credit card information in order to close an invoice. Which of the following topics did the user recognize from the training?
Community Votes
84% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests hierarchical classification knowledge, trapping candidates who fixate on the keyword 'CFO' and select 'executive whaling' instead of recognizing the overarching training topic of social engineering.
This question evaluates a candidate's ability to classify a simulated phone-based manipulation attempt against specific attack terminology. The community consensus strongly confirms that impersonating an executive to extract sensitive data from an employee is fundamentally a social engineering technique.
Candidates frequently select 'Executive whaling' because they associate the mention of a high-ranking executive with whaling attacks. However, whaling specifically involves directly targeting the executive themselves, whereas this scenario uses the executive's identity merely as a pretext to manipulate a different target.
Community Discussion (22 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept Analysis
The scenario describes a voice-based manipulation attempt where an attacker impersonates the CFO to create false urgency and authority. This is a textbook example of pretexting, a subset of social engineering. Security awareness training programs categorize these human-centric manipulation tactics under the broader umbrella of social engineering, which encompasses vishing, phishing, tailgating, and other psychological exploitation methods.Why Option C is Correct
Social engineering is the correct answer because it represents the foundational training topic the user recognized. As noted by multiple community experts, the question explicitly asks for the "TOPIC" learned during training. Social engineering is the comprehensive discipline that teaches employees how to identify unauthorized requests, verify identities, and resist psychological pressure regardless of the specific attack vector used ([Comment 3], [Comment 13]).Why Other Options Are Incorrect
- Insider threat (A) refers to malicious or negligent actions originating from within the organization, such as disgruntled employees or compromised accounts. The caller was external.
- Email phishing (B) is incorrect because the attack occurred over a telephone call (vishing), not via electronic mail.
- Executive whaling (D) is a highly targeted form of spear-phishing aimed directly at C-suite executives. In this scenario, the CFO is not the recipient; they are being impersonated to trick a regular staff member. As highlighted in community discussions, whaling requires the executive to be the actual target ([Comment 4], [Comment 5], [Comment 12]).
Community Consensus & Exam Nuance
The overwhelming vote for Option C reflects a strong understanding of CompTIA's emphasis on conceptual accuracy over keyword matching. Exam writers intentionally include distractor terms that share vocabulary with the scenario to test precise definitions. Recognizing that "whaling" targets the whale, while "social engineering" covers the method of deception, is critical for passing SY0-701.Official Reference
- https://www.comptia.org/content/guidelines/security-plus-study-guide-objectives
- NIST Special Publication 800-50, Building an Information Technology Security Awareness and Training Program
- CompTIA Security+ SY0-701 Objective 1.2: Given a scenario, analyze the likely source of a security incident and determine appropriate courses of action
Exam Strategy
When faced with overlapping attack classifications, always prioritize the exact scope defined in the official objectives over intuitive keyword associations. If a question asks for a "topic" or "category," select the broader framework first, and reserve specific attack names only when the scenario perfectly matches their strict target profile and delivery method.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →