Identifying Social Engineering Tactics in Security Awareness Scenarios

After a security awareness training session, a user called the IT help desk and reported a suspicious call. The suspicious caller stated that the Chief Financial Officer wanted credit card information in order to close an invoice. Which of the following topics did the user recognize from the training?

  1. Insider threat
  2. Email phishing
  3. Social engineering Source Reference Answer
  4. Executive whaling

Community Votes

C
84%
D
16%

84% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests hierarchical classification knowledge, trapping candidates who fixate on the keyword 'CFO' and select 'executive whaling' instead of recognizing the overarching training topic of social engineering.

This question evaluates a candidate's ability to classify a simulated phone-based manipulation attempt against specific attack terminology. The community consensus strongly confirms that impersonating an executive to extract sensitive data from an employee is fundamentally a social engineering technique.

Candidates frequently select 'Executive whaling' because they associate the mention of a high-ranking executive with whaling attacks. However, whaling specifically involves directly targeting the executive themselves, whereas this scenario uses the executive's identity merely as a pretext to manipulate a different target.

Community Discussion (22 comments)

EXAMM3R 👍 20
Executive whaling is when the CFO is one being targeted, therefore the answer is C
geocis 👍 9
Answer is C....Social engineering is the practice of manipulating people into performing actions or divulging confidential information, often by impersonating someone else or creating a sense of urgency or trust. The suspicious caller in this scenario was trying to use social engineering to trick the user into giving away credit card information by pretending to be the CFO and asking for a payment. The user recognized this as a potential scam and reported it to the IT help desk. The other topics are not relevant to this situation.
edward0811 👍 1 Selected: C
The answer is C - We have to read the question carefully. At the end of the question, it says, "Which of the following TOPICS". The only one that truly qualifies as a "TOPIC" is social engineering. All the others are examples of social engineering.
TECHBOSS 👍 1 Selected: C
C: SOCIAL ENGINEERING. The two parties are the IT individual and the CALLER threatening AS IF they were the CFO. Whaling involves ACTULLY targeting the CFO. "IT" is the target.
917a0a9 👍 3 Selected: C
"executive whaling" is a term used in cybersecurity, referring to a highly targeted phishing attack specifically aimed at high-level executives like CEOs, CFOs, or other senior leaders within an organization, essentially meaning the "whale" in this analogy is the high-value target, the executive with significant access to sensitive information Answer is social engineering. The CFO WAS NOT the target in this scenario
courtr 👍 1 Selected: C
voice phishing is a type of social engineering. executive whaling would only be the case if the CFO was the target receiving the call.
myazureexams 👍 1 Selected: C
C- SOCIAL engineering The user recognized the topic of social engineering from the security awareness training session. Executive whaling, also known as "whaling," is a specific type of social engineering attack where the attacker impersonates a high-ranking executive. In this scenario, the user identified a social engineering attempt, even if they didn't specify executive whaling.
PAWarriors 👍 1 Selected: C
Correct answer is C. The scenario described is social engineering. As mentioned by other members, "executive whaling" is a form of spear phishing that targets high-profile individuals, like CEOs or CFOs. In this case a regular "user" is the one that received the call a not a high-profile individual.
Cyber_Texas 👍 1 Selected: C
It is C because someone is pretending to be someone else that would classify as social engineering
Crucible_Bro 👍 1 Selected: C
someone is pretending to be someone within the company with authority. Social engineering.
dbrowndiver 👍 5 Selected: C
Suspicious caller impersonated someone with authority (CFO) to trick the user into providing credit card information. This is a classic example of social engineering, where the attacker exploits trust and urgency to extract sensitive data. The scenario matches the characteristics of a social engineering attack, as it involves manipulating the victim through a phone call rather than using technological methods or digital communication channels.
Dlove 👍 5 Selected: C
C. Social Engineering We have to pay attention to the question because they can be very tricky. They didn't specifically target the CFO they simply mentioned the person and said they wanted credit card info. Based on the question that we have the correct answer is C
Bimbo_12 👍 4 Selected: C
C. Social engineering Explanation: Social engineering is a manipulation technique that exploits human error to gain private information, access, or valuables. In this scenario, the suspicious caller was attempting to deceive the user into providing credit card information by falsely claiming to be acting on behalf of the Chief Financial Officer. This tactic is a classic example of social engineering, where the attacker uses social manipulation rather than technical hacking methods to obtain sensitive information. It is not D because this is a type of phishing attack that specifically targets high-profile executives (also known as "whales") to steal sensitive information. While the scenario does involve the mention of a high-ranking executive, it is broader in scope and fits under the general category of social engineering rather than a specific whaling attack through email.
TheMichael 👍 3 Selected: C
How I understand it is Whaling is when they impersonate an executive, executive whaling is when they target an executive (spearfishing in a sense), and social engineering is a broad form of trickery to deceive whoever the target is (not specific) to divulge information.
78fcd3e 👍 2 Selected: C
In CompTIA's lessons for 701, the only reference I could find for "whaling" is a definition of "targeting employees that have influential roles." I'm going with C. Social engineering
mnphobby 👍 3
C Whaling is send email to the Ceo
b3a128a 👍 3
It has to be C because the caller is stating the CFO wants the information, he is not saying he is the CFO.. also the term is whaling, not executive whaling
101e7ca 👍 3 Selected: C
For the 601 exam Whaling referred to the CEO being hit by a phishing attack...ie email. It targets a high value individual through email. This scenario says that someone called in to impersonate the CFO (high level individual) which is social engineering. There seems to be a term called Executive Phishing but not Executive Whaling. This could be a CompTIA question where they mix the terms to catch you out. Doesn't help that in the real world we often use these terms interchangeably.
AbdullahMohammad251 👍 5 Selected: D
Social engineering encompasses a wide variety of techniques and psychological tactics to exploit human vulnerabilities. - Whaling: This is a type of social engineering attack that targets high-profile individuals by impersonating them to deceive other employees into divulging sensitive information or performing actions that compromise security. -The scenario described clearly involved the impersonation of a CFO, which makes option D the correct answer.
johnysmith 👍 1 Selected: D
Executive Whaling
cdsu 👍 4
C: Social enginerring This involves impersonation of an executive, it is done via a phone call rather than an email
Shaman73 👍 3
D. Executive whaling

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept Analysis

The scenario describes a voice-based manipulation attempt where an attacker impersonates the CFO to create false urgency and authority. This is a textbook example of pretexting, a subset of social engineering. Security awareness training programs categorize these human-centric manipulation tactics under the broader umbrella of social engineering, which encompasses vishing, phishing, tailgating, and other psychological exploitation methods.

Why Option C is Correct

Social engineering is the correct answer because it represents the foundational training topic the user recognized. As noted by multiple community experts, the question explicitly asks for the "TOPIC" learned during training. Social engineering is the comprehensive discipline that teaches employees how to identify unauthorized requests, verify identities, and resist psychological pressure regardless of the specific attack vector used ([Comment 3], [Comment 13]).

Why Other Options Are Incorrect

  • Insider threat (A) refers to malicious or negligent actions originating from within the organization, such as disgruntled employees or compromised accounts. The caller was external.
  • Email phishing (B) is incorrect because the attack occurred over a telephone call (vishing), not via electronic mail.
  • Executive whaling (D) is a highly targeted form of spear-phishing aimed directly at C-suite executives. In this scenario, the CFO is not the recipient; they are being impersonated to trick a regular staff member. As highlighted in community discussions, whaling requires the executive to be the actual target ([Comment 4], [Comment 5], [Comment 12]).

Community Consensus & Exam Nuance

The overwhelming vote for Option C reflects a strong understanding of CompTIA's emphasis on conceptual accuracy over keyword matching. Exam writers intentionally include distractor terms that share vocabulary with the scenario to test precise definitions. Recognizing that "whaling" targets the whale, while "social engineering" covers the method of deception, is critical for passing SY0-701.

Official Reference

Exam Strategy

When faced with overlapping attack classifications, always prioritize the exact scope defined in the official objectives over intuitive keyword associations. If a question asks for a "topic" or "category," select the broader framework first, and reserve specific attack names only when the scenario perfectly matches their strict target profile and delivery method.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide