
EC-CouncilCertified Penetration Testing Professional
Domain 2Objective 2
Social Engineering Penetration Testing CPENT Practice Questions (Page 2)
Part of the Information Gathering and Social Engineering domain, which makes up ~9% of our current practice bank.
36questions here
8free pages
6concepts
Questions 6–10
- 6
In a penetration test report, which section should include the social engineering techniques used, the number of users who fell victim, and the specific information or access obtained?
Select an answer first - 7
A penetration tester calls a company's help desk, claims to be a new employee who forgot their password, and provides a fake employee ID to reset the password. Which social engineering technique is being used?
Select an answer first - 8
The Social-Engineer Toolkit (SET) is a framework that includes multiple attack vectors. Which of the following is a feature of SET?
Select an answer first - 9
A penetration tester is using GoPhish for a phishing campaign. The client wants to track not only clicks but also which users submit data on the landing page. The tester has set up the campaign but notices that the 'submitted data' report is empty even though users have clicked the link. Which configuration is most likely the cause?
Select an answer first - 10
A client wants to test their employees' awareness of smishing attacks. They want to see if employees will click on a link in a text message that appears to be from a legitimate source. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.