
EC-CouncilCertified Ethical Hacker
Domain 4Objective 2
Social Engineering and Phishing CEH Practice Questions (Page 5)
Part of the Network and Perimeter Hacking domain, which makes up ~9% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~9–14 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
6concepts
Questions 21–25
- 21
An attacker creates a fake scenario, such as claiming to be from the IT department, to convince an employee to reveal their password. Which social engineering vector is being used?
Select an answer first - 22
A user receives a text message that appears to be from their bank, stating that their account has been locked and they must click a link to verify their identity. The link points to a domain that looks similar to the bank's official domain but with a typo. Which type of phishing attack is this?
Select an answer first - 23
What is the primary goal of security awareness training in the context of social engineering?
Select an answer first - 24
A penetration tester is conducting a social engineering assessment for a client. The client wants to test the effectiveness of their security awareness training. Which approach would provide the most realistic and useful results?
Select an answer first - 25
In the context of social engineering, which psychological principle is most directly exploited when an attacker impersonates a senior executive and pressures an employee to act quickly without verifying the request?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.