312-50 exam dumps

312-50 practice question 211 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 211

Single answer▪ Social Engineering Techniques

During an authorized social engineering assessment for a financial services company, you are asked to evaluate how susceptible employees are to pretexting without causing operational disruption or violating the rules of engagement. The client allows phone-based testing of the help desk and requires that no passwords be requested or reset during the exercise. Which approach is the MOST appropriate to test pretexting effectiveness under these constraints?

  1. A

    Call the help desk while impersonating a new employee, claim you cannot access the VPN, and attempt to persuade the analyst to disclose internal onboarding steps or security verification weaknesses without asking for credentials or a reset

  2. B

    Send a spoofed email to all employees with a link to a cloned SSO portal and measure how many users submit their usernames and passwords

  3. C

    Tailgate into the office behind an employee carrying boxes and then search desks for written passwords to validate physical security gaps

  4. D

    Call the help desk pretending to be the CIO and pressure the analyst into immediately changing a privileged account password to a value you provide

Show answer and explanation

Correct answer: A

Explanation

The key to this question is applying social engineering knowledge within an authorized assessment's rules of engagement. Pretexting involves creating a believable fabricated scenario to influence a target into revealing information or bypassing normal procedure. In this case, the client specifically authorized phone-based testing of the help desk and prohibited requesting or resetting passwords. Therefore, the most appropriate method is a controlled phone pretext that measures whether help desk staff properly validate identity and limit disclosure of sensitive process information. This aligns with common security testing best practices: stay within written authorization, minimize business disruption, and avoid collecting unnecessary sensitive data. These principles are consistent with professional penetration testing standards and guidance such as rules-of-engagement practices described in NIST SP 800-115, which emphasizes clearly defined scope, limitations, and approved test methods.

  • A. Correct.

    Correct. This is a classic pretexting scenario conducted over the phone and stays within the stated constraints: it targets the help desk, avoids requesting passwords, and does not involve an actual password reset. It assesses whether staff follow identity verification procedures and whether they reveal useful process details that could aid a real attacker. In CEH-style scenarios, the best answer is the one that matches both the attack technique being tested and the engagement limitations.

  • B. Incorrect.

    Incorrect. This describes a phishing credential-harvesting exercise, not pretexting focused on the help desk. It also violates the requirement not to request passwords, because a cloned SSO portal is specifically designed to collect credentials. A candidate might choose this because phishing is a common social engineering method, but it does not align with the scope and constraints given.

  • C. Incorrect.

    Incorrect. This is primarily a physical social engineering and security assessment technique involving tailgating and inspection of the workspace, not a phone-based pretexting test of the help desk. It also introduces operational and legal concerns beyond the authorized method described. The misconception is assuming any social engineering activity is acceptable even when the engagement narrowly defines the channel and target.

  • D. Incorrect.

    Incorrect. This is pretexting in form, but it explicitly violates the rule prohibiting password resets. It also introduces unnecessary risk by targeting a privileged account and using coercive authority pressure. Someone might pick it because impersonating an executive is a realistic pretext, but the best answer must remain within the rules of engagement.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam