Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 2Objective 2

Social Engineering Penetration Testing CPENT Practice Questions (Page 7)

Part of the Information Gathering and Social Engineering domain, which makes up ~9% of our current practice bank.

36questions here
8free pages
6concepts

Questions 31–35

  1. 31foundation · easy

    A penetration tester calls a target employee, pretends to be from the company's IT department, and asks for the employee's password to 'fix a network issue.' Which social engineering attack vector is being used?

    Select an answer first
  2. 32application · medium

    A penetration tester is conducting a vishing attack and needs to obtain a user's password. The tester calls the user, pretending to be from the IT help desk, and claims there is a security issue that requires the user to verify their password. Which social engineering principle is the tester primarily exploiting?

    Select an answer first
  3. 33foundation · easy

    Which of the following is an effective mitigation strategy to reduce the risk of social engineering attacks in an organization?

    Select an answer first
  4. 34application · medium

    A penetration tester is executing a phishing campaign and needs to ensure that the campaign does not trigger the client's email security filters. The tester has access to the client's email gateway. Which action is most effective in avoiding detection by email filters?

    Select an answer first
  5. 35application · medium

    You are conducting a physical social engineering test for a client. The goal is to see if you can obtain sensitive information from employees by observing them as they enter their access codes on a keypad. Which technique is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.