What Technique Is Used When an Attacker Poses as the CEO to Trick an Employee?
An attacker posing as the Chief Executive Officer calls an employee and instructs the employee to buy gift cards. Which of the following techniques is the attacker using?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your ability to distinguish between broad impersonation tactics and targeted phishing variants like whaling, with the common trap being confusion over whether mentioning a CEO automatically classifies the attack as whaling.
This question examines social engineering tactics where attackers leverage authority figures to manipulate targets into unauthorized actions. The community overwhelmingly agrees that Impersonating is the correct answer, as the attack targets a regular employee rather than a high-level executive.
Candidates frequently select Whaling, mistaking the presence of a CEO in the scenario as the defining factor. However, whaling specifically targets high-profile individuals themselves, whereas this scenario describes an attacker posing as an executive to deceive a standard employee, making impersonation the precise technical term.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Core Concept
This question evaluates your knowledge of social engineering techniques, specifically how threat actors manipulate human psychology to bypass security controls. The scenario describes a classic voice-based manipulation tactic where the adversary leverages perceived authority to coerce compliance.Why Impersonating is Correct
Impersonating occurs when an attacker deliberately assumes the identity of another person to gain trust and extract resources. In this case, the attacker calls an employee and poses as the Chief Executive Officer. As highlighted by multiple community voters, the critical distinction lies in the target: since the victim is a regular employee rather than a senior executive, the technique is accurately classified as impersonation. The attacker exploits organizational hierarchy and the employee's natural deference to leadership.Why Other Options Are Incorrect
- Smishing involves delivering malicious links or instructions via SMS text messages. Since the scenario specifies a phone call, this option is immediately eliminated.
- Disinformation refers to the deliberate creation and spread of false information to mislead audiences, typically in public relations or information warfare contexts, not direct interpersonal manipulation for financial gain.
- Whaling is a highly targeted subset of phishing that specifically aims at high-profile individuals such as CEOs, CFOs, or board members. While the attacker is posing as a CEO, the actual victim in this scenario is an employee. Community discussions frequently highlight this exact trap: seeing "CEO" triggers the whaling association, but certification exams require precision based on who is being attacked versus who is being mimicked.
Official Reference
Exam Strategy
Always identify both the attacker's disguise and the actual target before selecting a social engineering answer. If the scenario mentions a high-ranking title but the victim is a junior staff member, choose the broader impersonation option rather than whaling or VIP-targeted attacks.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →