312-50 exam dumps

312-50 practice question 209 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 209

Single answer▪ Social Engineering Concepts

An organization has authorized a CEH-certified consultant to perform a social engineering assessment against its finance department. The rules of engagement state that the consultant may test employee susceptibility to phishing but must minimize operational disruption and avoid requesting sensitive data such as passwords or banking details. The consultant plans to send an email that appears to come from the internal IT help desk and wants to measure which employees are most likely to trust the message. Which approach is the MOST appropriate for this assessment?

  1. A

    Send a spoofed IT help desk email containing a link to a controlled landing page that records clicks and asks users only to acknowledge a fake policy update, without collecting credentials

  2. B

    Send a spoofed CEO email directing employees to urgently reply with their VPN usernames and passwords so the consultant can measure compliance under pressure

  3. C

    Call finance employees while impersonating the bank's fraud department and ask them to verify recent wire transfers using real account data provided by the client

  4. D

    Email a malicious attachment disguised as an invoice so the consultant can test whether endpoint protection blocks malware execution

Show answer and explanation

Correct answer: A

Explanation

The best answer is the controlled phishing email with a benign landing page because it directly supports the assessment goal: measuring employee susceptibility to a realistic social engineering pretext while staying within scope. In professional engagements, social engineering tests must follow written rules of engagement, define prohibited data collection, and use safe payloads or non-harmful tracking methods. A common best practice is to measure opens, clicks, and form submissions on a controlled page without collecting real credentials unless explicitly authorized. This is consistent with ethical testing principles emphasized in penetration testing standards and engagement scoping guidance, such as maintaining client-approved boundaries, minimizing business impact, and avoiding unnecessary collection of sensitive information.

  • A. Correct.

    Correct. This approach aligns with the rules of engagement and common social engineering testing best practices. It measures trust and click-through behavior without requesting prohibited sensitive data such as passwords or banking information. Using a controlled landing page is a standard way to safely assess phishing susceptibility while minimizing risk and operational impact.

  • B. Incorrect.

    Incorrect. Although urgency and authority are common social engineering themes, requesting VPN usernames and passwords violates the stated rules of engagement because it seeks sensitive authentication data. In a legitimate assessment, credential harvesting must be explicitly authorized and tightly controlled.

  • C. Incorrect.

    Incorrect. Voice phishing is a valid social engineering method in some engagements, but this option is not the most appropriate here. It goes beyond the permitted phishing-focused scope and introduces unnecessary risk by involving real financial transaction context and potentially sensitive banking details.

  • D. Incorrect.

    Incorrect. Delivering a malicious attachment shifts the activity toward malware delivery and endpoint security testing rather than a low-impact social engineering assessment. It creates avoidable operational risk and does not fit the requirement to minimize disruption.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam