
EC-CouncilCertified Penetration Testing Professional
Domain 2Objective 2
Social Engineering Penetration Testing CPENT Practice Questions (Page 1)
Part of the Information Gathering and Social Engineering domain, which makes up ~9% of our current practice bank.
36questions here
8free pages
6concepts
Questions 1–5
- 1
A penetration tester is planning a phishing campaign against a client's finance department. The client requires that the campaign use a realistic pretext, track which users click the link, and provide a report that includes metrics for management. The tester has access to GoPhish and the client's approved email gateway. Which approach best meets the client's requirements?
Select an answer first - 2
A penetration tester waits for an employee to badge into a secured office and then follows closely behind without using a badge. Which physical social engineering technique is being used?
Select an answer first - 3
You are performing a physical social engineering test for a client. The goal is to obtain sensitive documents from a shredding bin outside the building. Which technique is most appropriate and least likely to be noticed?
Select an answer first - 4
Which open-source tool is specifically designed to automate the creation and management of phishing campaigns, including email templates, landing pages, and tracking?
Select an answer first - 5
When setting up a landing page for a phishing campaign, what is the primary purpose of hosting the page on a domain that closely resembles the target organization's legitimate domain?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.