
EC-CouncilCertified Penetration Testing Professional
Domain 2Objective 2
Social Engineering Penetration Testing CPENT Practice Questions (Page 6)
Part of the Information Gathering and Social Engineering domain, which makes up ~9% of our current practice bank.
36questions here
8free pages
6concepts
Questions 26–30
- 26
During a penetration test, an assessor sends a fraudulent email that appears to come from the target organization's IT help desk, asking the recipient to verify their account credentials by clicking a link. Which social engineering attack vector is being used?
Select an answer first - 27
A penetration tester is setting up a phishing campaign for a client. The client requires that the campaign be realistic but also that the tester capture credentials from users who fall for it. The tester plans to use GoPhish. What is the most effective way to capture credentials while maintaining realism?
Select an answer first - 28
You are using GoPhish to run a phishing campaign for a client. You need to send a test email to a small group of users and track who opens the email and clicks the link. Which feature should you use?
Select an answer first - 29
During a social engineering test, you need to obtain the Wi-Fi password from an employee. You have learned that the employee is a fan of a local sports team. Which pretext is most likely to succeed?
Select an answer first - 30
A client wants to test their employees' susceptibility to vishing attacks. They want to see if employees will reveal their passwords over the phone. Which approach is most effective and ethical?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.