312-50 exam dumps

312-50 practice question 212 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 212

Single answer▪ Social Engineering Techniques

During an authorized CEH engagement, a company asks you to assess employee susceptibility to social engineering without deploying malware, capturing credentials, or causing operational disruption. The client wants a technique that can be executed remotely and measured objectively. Which approach is the MOST appropriate to meet these requirements?

  1. A

    Conduct a phishing awareness assessment by sending a controlled email that directs users to a harmless landing page and records click-through rates

  2. B

    Call the help desk while impersonating the CIO and pressure staff to reset an employee password so you can verify identity-check procedures

  3. C

    Leave branded USB drives in the parking lot and measure how many are inserted into corporate workstations

  4. D

    Tailgate into the building during shift change and ask employees to hold secure doors open so you can test physical security awareness

Show answer and explanation

Correct answer: A

Explanation

The key requirements are remote execution, objective measurement, and minimal risk: no malware, no credential capture, and no disruption. A controlled phishing awareness assessment best fits those constraints. In professional engagements, social engineering activities should be explicitly defined in the rules of engagement, including whether credential harvesting, impersonation of executives, physical access attempts, or removable media tests are allowed. Industry best practices for phishing simulations emphasize benign payloads, safe landing pages, logging of user actions, and coordination with the client to avoid business impact. This aligns with common security awareness guidance from organizations such as NIST, which stresses user training and testing, and with ethical testing practices that require clear authorization and minimized risk.

  • A. Correct.

    Correct. A controlled phishing simulation is a standard, measurable social engineering assessment that can be performed remotely and aligned with strict rules of engagement. By using a benign landing page instead of malware or credential collection, the tester can objectively measure user behavior such as email opens, link clicks, and reporting rates while minimizing operational and legal risk.

  • B. Incorrect.

    Incorrect. This is a form of pretexting/vishing and can be realistic, but it introduces higher risk because it may trigger actual account changes, disrupt support workflows, or pressure staff into violating policy in a live environment. It is also less scalable and less objectively measurable than a controlled phishing campaign for the client's stated constraints.

  • C. Incorrect.

    Incorrect. USB baiting is a valid social engineering technique, but it is not remote and can create operational and security risk if users insert unknown media into systems. Even when using harmless files, this method depends on physical placement and may conflict with the client's requirement to avoid disruption.

  • D. Incorrect.

    Incorrect. Tailgating is a physical social engineering technique, not a remote one. While it can test employee security awareness, it does not satisfy the requirement for remote execution and may create safety or access-control issues outside the client's stated scope.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam