
EC-CouncilCertified Security Specialist
Domain 3Objective 6
Social Engineering Techniques and Countermeasures ECSS Practice Questions (Page 10)
Part of the Ethical Hacking Fundamentals and Core Attacks domain, which makes up ~17% of our current practice bank.
51questions here
11free pages
10concepts
Questions 46–50
- 46
Why is it important for security awareness training to be conducted regularly rather than only once?
Select an answer first - 47
An employee receives a suspicious email with an attachment that they did not request. They do not open it. What should the employee do first according to incident reporting procedures?
Select an answer first - 48
A receptionist finds a USB drive labeled 'Employee Bonuses 2024' in the parking lot and plugs it into a work computer to see the contents. What type of social engineering attack is this, and what countermeasure would be most effective?
Select an answer first - 49
An attacker calls an employee, claiming to be from the company's security department, and asks the employee to verify their username and password to 'confirm their identity' after a recent breach. Which social engineering principle is being exploited, and what is the best response?
Select an answer first - 50
Which of the following best describes the typical lifecycle of a social engineering attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.