Courseiva
Security Operations →easyMultiple Choice

ISC2 CC Security Operations Practice Question

A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?

⚠ Common exam trap

The trap here is treating any request for an MFA code as routine support activity instead of recognizing that unsolicited code requests are a hallmark of social engineering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authority combined with urgency, because the caller impersonates support staff and pressures the administrator to act immediately.

The caller fabricates a critical server problem while posing as help desk personnel, which combines impersonated authority with manufactured urgency. Because the administrator never initiated an MFA challenge, no legitimate support process would require the code to be read aloud. The correct response is to refuse, hang up, and verify through a known internal channel. This scenario tests recognition of pretexting and MFA code theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reciprocity, because the caller previously helped the administrator with a ticket and now expects a favor in return.

    Why it's wrong here

    Reciprocity relies on a prior gift or favor that creates a sense of obligation. The scenario states only that the caller claims to be from the help desk and reports a server issue; no earlier assistance is mentioned. The administrator is being manipulated through impersonated authority and manufactured urgency, so reciprocity does not describe the technique in play.

  • ✗

    Consensus, because the caller claims that other administrators have already shared their codes to fix the same problem.

    Why it's wrong here

    Consensus, or social proof, works by showing that peers have already complied, which normalizes the requested action. The caller here never references what coworkers did; the appeal is to the administrator's sense of duty and fear of a server outage. Although consensus can appear in vishing, it is not the principle described in this scenario.

  • ✓

    Authority combined with urgency, because the caller impersonates support staff and pressures the administrator to act immediately.

    Why this is correct

    The caller claims to be help desk staff and invents a critical server issue to create time pressure. This is a classic pretext that leverages authority and urgency so the victim bypasses normal verification. Because the administrator did not initiate the MFA challenge, sharing the code would hand over a second factor and allow account takeover. Recognizing unsolicited authority claims is a core security operations skill.

  • ✗

    Scarcity, because the caller implies that only a limited number of support slots are available for the server repair.

    Why it's wrong here

    Scarcity exploits the fear of missing a limited opportunity, such as a one-time discount or a closing registration window. Nothing in the scenario suggests a limited resource or deadline of that kind; the pressure comes from the claimed server emergency and the caller's implied authority, not from limited availability. Choosing scarcity misidentifies the psychological lever being used.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.