312-50 Question 210
Single answer▪ Social Engineering ConceptsDuring an authorized social engineering assessment, a security consultant learns from public social media posts that several employees of a manufacturing company are attending an industry conference. The consultant wants to evaluate whether users will disclose credentials through a realistic phishing campaign while minimizing the chance of immediate technical detection by the company's secure email gateway. Which approach would be the MOST effective and ethically appropriate for this goal?
- A
Send a mass email from a free public email account with a generic message claiming all employees must immediately reset their passwords using an attached executable
- B
Register a look-alike domain related to the conference, craft a targeted email referencing the event schedule, and direct selected employees to a controlled credential-harvesting page approved in the rules of engagement
- C
Call the company help desk pretending to be the CEO and demand employee passwords so the consultant can validate account complexity more quickly
- D
Drop infected USB drives labeled with the conference name in the company parking lot to see who executes the payload and sends credentials back
Show answer and explanation
Correct answer: B
Explanation
The best answer is the targeted spear-phishing approach using a believable pretext derived from open-source intelligence. In social engineering assessments, the most effective campaigns are context-aware, limited to approved targets, and designed around clear objectives such as credential capture, reporting rates, or click rates. CEH candidates should recognize that spear phishing is more effective than generic phishing because personalization increases trust and engagement. From a best-practice perspective, authorized social engineering must remain within the signed rules of engagement, including approved domains, targets, collection methods, and handling of captured credentials. Industry guidance for penetration testing and social engineering engagements commonly emphasizes written authorization, scope control, minimal operational impact, and safe handling of collected data. This makes a controlled, conference-themed credential-harvesting site the most practical and ethically appropriate method in this scenario.
- A. Incorrect.
This is incorrect because a mass email from a free public email provider with a generic urgent message and an attached executable is both unrealistic and highly likely to be blocked by spam and malware controls. It also does a poor job of testing social engineering effectiveness because the indicators are too obvious. In a CEH context, effective phishing simulations are typically tailored, pretext-driven, and aligned with the target's environment rather than relying on crude bait.
- B. Correct.
This is correct because it uses a realistic pretext based on OSINT gathered from social media, making the message more credible and relevant to the targets. A look-alike domain and conference-themed content can reduce suspicion and better simulate real spear-phishing tactics. Directing users to a controlled credential-harvesting page is a common, authorized way to measure whether users will submit credentials, provided it is explicitly approved in the engagement scope and rules of engagement. This tests susceptibility while keeping the exercise focused and measurable.
- C. Incorrect.
This is incorrect because requesting passwords directly from the help desk is generally outside what should be done unless explicitly authorized, and it targets staff-to-staff verification processes rather than the stated goal of evaluating whether users disclose credentials through a phishing campaign. It also introduces unnecessary ethical and operational risk. While impersonation is a social engineering technique, this option does not best match the scenario requirements.
- D. Incorrect.
This is incorrect because leaving infected USB drives introduces malware execution risk and shifts the assessment toward baiting with removable media rather than a phishing campaign. The scenario specifically focuses on testing credential disclosure through email-based social engineering while minimizing technical detection by email defenses. Even in authorized engagements, using infected media is far more disruptive and requires separate approval and controls.