nerdexam
CompTIA

SY0-501 · Question #86

Recently several employees were victims of a phishing email that appeared to originate from the company president. The email claimed the employees would be disciplined if they did not click on a…

The correct answer is A. Authority. This social engineering attack successfully manipulated employees by impersonating the company president and threatening disciplinary action, thereby exploiting the principle of authority.

Submitted by lukas.cz· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

Recently several employees were victims of a phishing email that appeared to originate from the company president. The email claimed the employees would be disciplined if they did not click on a malicious link in the message. Which of the following principles of social engineering made this attack successful?

Options

  • AAuthority
  • BSpamming
  • CSocial proof
  • DScarcity

How the community answered

(45 responses)
  • A
    73% (33)
  • B
    9% (4)
  • C
    4% (2)
  • D
    13% (6)

Why each option

This social engineering attack successfully manipulated employees by impersonating the company president and threatening disciplinary action, thereby exploiting the principle of authority.

AAuthorityCorrect

The attackers leveraged the perceived power and legitimacy of the company president, a figure of authority, to induce fear and compliance among employees. The threat of disciplinary action further exploited this principle, making employees more likely to obey the malicious instructions without critical evaluation.

BSpamming

Spamming refers to the mass distribution of unsolicited messages, which is a delivery method for phishing attacks, not a psychological principle of social engineering that manipulates human behavior.

CSocial proof

Social proof relies on individuals conforming to actions or beliefs of a larger group, assuming those actions are correct, which is not evident in this scenario where a single authority figure is impersonated.

DScarcity

Scarcity involves creating a sense of urgency or limited availability to compel action, but the primary motivator here was the threat from a high-ranking individual, not the perceived dwindling of an opportunity or resource.

Concept tested: Social engineering principle of authority (pretexting)

Source: https://learn.microsoft.com/en-us/training/modules/describe-social-engineering-dos-ddos-attacks-sc-900/3-describe-social-engineering

Topics

#social engineering#authority principle#phishing#psychological manipulation

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice