After a security awareness training session, a user called the IT help desk and reported a suspicious call. The suspicious caller stated that the Chief Financial Officer wanted credit card information in order to close an invoice. Which of the following topics did the user recognize from the training?
Choose an answer
Tap an option to check your answer.
Correct answer: Social engineering.
Why this is the answer
The user recognized social engineering, which is the psychological manipulation of people into performing actions or divulging confidential information. The suspicious caller used a pretext (the CFO needing credit card information for an invoice) to trick the user, a classic social engineering tactic. Insider threat refers to a malicious act by a person within the organization, which doesn't fit this scenario as the caller was external. Email phishing specifically involves fraudulent emails, whereas this was a phone call. Executive whaling is a targeted phishing attack aimed at high-level executives, usually via email, and while the CFO was mentioned, the attack vector was a phone call to a regular user, not the CFO directly.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed