
EC-CouncilCertified Security Specialist
Domain 3Objective 6
Social Engineering Techniques and Countermeasures ECSS Practice Questions (Page 1)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
10concepts
Questions 1–5
- 1
An employee receives a suspicious email that asks for login credentials to a company portal. The employee does not click any links and wants to report it. What is the most appropriate action?
Select an answer first - 2
A social engineer calls an employee, claiming to be from the IT department and stating that they need the employee's login credentials to fix a critical server issue. Which technique is being used?
Select an answer first - 3
An attacker sends an email to a company's accounts payable department, posing as a vendor, and claims that the payment details have changed. The email includes a link to a fake invoice portal. Which social engineering attack vector is being used, and what psychological principle is primarily exploited?
Select an answer first - 4
Which social engineering attack specifically targets high-level executives such as CEOs or CFOs?
Select an answer first - 5
An attacker calls an employee, claiming to be from the company's legal department, and asks for the employee's home address and date of birth for 'compliance purposes'. The employee provides the information. Which social engineering principle is being exploited, and what is the best countermeasure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.