
EC-CouncilCertified Ethical Hacker
Domain 4Objective 2
Social Engineering and Phishing CEH Practice Questions (Page 3)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 11–15
- 11
During a social engineering attack, the attacker gathers information about the target, establishes a relationship, and then exploits the relationship to obtain sensitive data. Which phase of the social engineering attack cycle does the exploitation occur in?
Select an answer first - 12
A penetration tester is planning a social engineering assessment for a client. The client has a strong security awareness program and employees are trained to spot phishing emails. The tester needs to achieve a high success rate while minimizing the risk of being detected. Which approach is most likely to succeed?
Select an answer first - 13
A financial analyst receives an email that appears to be from the company's CEO, urgently requesting a wire transfer to a new vendor. The email address is ceo@company-legal.com, and the message contains a link to a document titled 'Invoice_Urgent.docm'. The analyst is about to comply. Which action should the analyst take first?
Select an answer first - 14
A security analyst is reviewing a suspicious email reported by an employee. The email claims to be from a well-known shipping company, contains an attachment named 'invoice_2024.exe', and the sender address is 'support@shipment-tracking-now.com'. The email body has a sense of urgency and asks the employee to open the attachment to avoid a delivery delay. Which two indicators most strongly suggest a malicious phishing email?
Select an answer first - 15
A penetration tester is conducting a social engineering assessment. The client has a strict policy that all visitors must be escorted, and the front desk is staffed. The tester wants to gain physical access to the server room. Which approach is most likely to succeed while minimizing the risk of detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.