29. After a security awareness training session, a user called the IT help desk and reported a suspicious call. The suspicious caller stated that the Chief Financial Officer wanted credit card information in order to close an invoice. Which of the following topics did the user recognize from the training?

Answer: C

Explanation:

The user recognized social engineering from the training.

The user's report of a suspicious call involving a request for credit card information indicates an awareness of social engineering tactics. This type of manipulation exploits human psychology to gain sensitive information, which aligns with the call's context where the impersonation of a high-ranking official was used.

A) Insider threat

Insider threats refer to security risks that originate from within the organization, typically involving employees or contractors. In this scenario, the user identified an external threat rather than a threat from within, making this option incorrect.

B) Email phishing

Email phishing specifically involves fraudulent attempts to obtain sensitive information through deceptive emails. While related, the user's experience pertained to a phone call rather than an email communication, so this option does not fit the context.

C) Social engineering

Social engineering is the practice of manipulating individuals into divulging confidential information by exploiting psychological tactics. The user's recognition of the suspicious call requesting credit card information under the guise of authority exemplifies this concept accurately.

D) Executive whaling

Executive whaling is a specific form of phishing targeting high-profile individuals within an organization, often involving impersonation of executives. While the call involved impersonation of a CFO, the broader term "social engineering" encompasses this tactic and is therefore the more appropriate classification in this context.

Conclusion

The correct identification of social engineering highlights the user's understanding of how attackers manipulate individuals to gain sensitive information. Other options either misinterpret the nature of the threat or do not accurately reflect the context of the user's experience. This underscores the importance of recognizing various security threats as part of effective training.