Question

Difficulty: MediumSocial Engineering Attacks and Vectors

An IT administrator receives an unverified request for sensitive internal network topology diagrams. When the administrator hesitates to comply, the requester claims that three senior network engineers in the department have already submitted their respective section diagrams for the ongoing audit. Reassured that colleagues have already complied, the administrator releases the requested files. Which of the following principles of influence did the attacker primarily exploit?

  1. ConsensusAnswer
  2. B
    Intimidation
  3. C
    Scarcity
  4. D
    Urgency

Answer

Consensus
Consensus (or social proof) occurs when an attacker persuades a target to take an action by demonstrating or claiming that others—specifically peers or coworkers—have already done so. In this scenario, stating that senior engineers in the same department had already provided their diagrams led the target to believe compliance was standard and safe.

Step-by-Step Solution

1
Analyze the attacker's psychological trigger described in the scenario.
The attacker persuaded the victim by stating that three peer engineers had already submitted their portion of the requested data.
Identifying the narrative device used to gain trust and compliance.
2
Map the observed psychological trigger to standard social engineering principles of influence.
Demonstrating that peers or equals have already complied defines the Consensus (or Social Proof) principle.
Matching attacker tactics against established social engineering frameworks.
3
Differentiate Consensus from related principles such as Authority, Urgency, or Intimidation.
Unlike Authority (which relies on rank) or Urgency (which relies on time pressure), Consensus relies on perceived peer validation.
Confirming the single best answer based on specific scenario details.

Key Concept

Principles of Influence - Consensus (Social Proof)
Rate this question