ISC2 CC Security Operations Practice Question
A junior administrator at a healthcare company receives a call from someone claiming to be from the IT help desk. The caller says there is a critical server issue and asks the administrator to read back the six-digit code just sent to their phone. The administrator has not requested any password reset or MFA challenge. Which social engineering principle is the caller most likely exploiting?
⚠ Common exam trap
The trap here is treating any request for an MFA code as routine support activity instead of recognizing that unsolicited code requests are a hallmark of social engineering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authority combined with urgency, because the caller impersonates support staff and pressures the administrator to act immediately.
The caller fabricates a critical server problem while posing as help desk personnel, which combines impersonated authority with manufactured urgency. Because the administrator never initiated an MFA challenge, no legitimate support process would require the code to be read aloud. The correct response is to refuse, hang up, and verify through a known internal channel. This scenario tests recognition of pretexting and MFA code theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reciprocity, because the caller previously helped the administrator with a ticket and now expects a favor in return.
Why it's wrong here
Reciprocity relies on a prior gift or favor that creates a sense of obligation. The scenario states only that the caller claims to be from the help desk and reports a server issue; no earlier assistance is mentioned. The administrator is being manipulated through impersonated authority and manufactured urgency, so reciprocity does not describe the technique in play.
- ✗
Consensus, because the caller claims that other administrators have already shared their codes to fix the same problem.
Why it's wrong here
Consensus, or social proof, works by showing that peers have already complied, which normalizes the requested action. The caller here never references what coworkers did; the appeal is to the administrator's sense of duty and fear of a server outage. Although consensus can appear in vishing, it is not the principle described in this scenario.
- ✓
Authority combined with urgency, because the caller impersonates support staff and pressures the administrator to act immediately.
Why this is correct
The caller claims to be help desk staff and invents a critical server issue to create time pressure. This is a classic pretext that leverages authority and urgency so the victim bypasses normal verification. Because the administrator did not initiate the MFA challenge, sharing the code would hand over a second factor and allow account takeover. Recognizing unsolicited authority claims is a core security operations skill.
- ✗
Scarcity, because the caller implies that only a limited number of support slots are available for the server repair.
Why it's wrong here
Scarcity exploits the fear of missing a limited opportunity, such as a one-time discount or a closing registration window. Nothing in the scenario suggests a limited resource or deadline of that kind; the pressure comes from the claimed server emergency and the caller's implied authority, not from limited availability. Choosing scarcity misidentifies the psychological lever being used.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.