
EC-CouncilEthical Hacking Essentials
Domain 4Objective 1
Social Engineering Concepts and Techniques EHE Practice Questions (Page 6)
Part of the Social Engineering domain, which makes up ~9% of our current practice bank.
44questions here
9free pages
5concepts
Questions 26–30
- 26
A security analyst is reviewing an incident where an attacker called the help desk, claimed to be a remote employee, and requested a password reset. The attacker had previously gathered the employee's name, department, and manager's name from the company's intranet. Which phase of the social engineering attack cycle is most critical for the success of this attack?
Select an answer first - 27
A medium-sized company has experienced multiple social engineering incidents: a phishing email led to a ransomware infection, a pretexting call resulted in a wire transfer to a fraudulent account, and a tailgating incident allowed an unauthorized person into a server room. The company has limited budget and must choose ONE control to implement that will reduce the risk of all three types of incidents. Which control is most effective?
Select an answer first - 28
A penetration tester is planning a social engineering engagement. The client wants to test both email and phone-based attacks. The tester has limited time and must choose between two scenarios: (1) a phishing email with a malicious attachment, or (2) a vishing call to the help desk requesting a password reset. The client's goal is to assess the effectiveness of their security awareness training. Which scenario is more likely to succeed, and why?
Select an answer first - 29
A penetration tester is conducting a social engineering assessment. The tester sends an email to employees stating that their accounts will be suspended in 30 minutes unless they verify their password by clicking a link. The email is not personalized and lacks the company logo. Despite this, several employees click the link. Which psychological principle is the tester primarily exploiting?
Select an answer first - 30
A social engineering attack uses an email that appears to be from the CEO, asking the finance department to urgently wire funds to a new vendor. The email address is slightly misspelled (e.g., ceo@company.com vs ceo@cornpany.com). Which psychological principle is the attacker primarily exploiting, and which technique is being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.