According to CEH v13 Social Engineering, social engineering attacks manipulate human trust rather than technical vulnerabilities. Option A describes a classic pretexting attack, where the attacker impersonates IT staff and fabricates a false issue to trick a victim into revealing credentials.
This scenario aligns perfectly with CEH definitions because:
The attacker relies on authority impersonation
The victim is socially manipulated
No technical exploitation is required
Option B is a legitimate security activity.
Option C is accidental malware introduction, not social engineering.
Option D is physical negligence exploitation, not direct social engineering interaction.
CEH v13 stresses that pretexting attacks are extremely effective against new employees who lack familiarity with procedures. Therefore, Option A is correct.