312-50 exam dumps

312-50 practice question 217 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 217

Single answer▪ Impersonation on Social Networking Sites

During a social engineering assessment authorized by a client, you discover that several employees have accepted connection requests from a fake social networking profile impersonating the company’s HR director. The profile uses the director’s name, photo, and job title, and has begun sending messages asking employees to review a "new benefits portal". The client asks which action would most effectively reduce the immediate risk from this impersonation attack while preserving evidence for investigation. What should the security team do FIRST?

  1. A

    Report the impersonating account through the social networking platform’s impersonation/fake account process, alert affected employees not to interact with the profile or links, and preserve screenshots, URLs, message headers, and timestamps as evidence

  2. B

    Create a second fake company profile to message the impersonator and gather more information before taking any other action

  3. C

    Ask employees to publicly comment on the fake profile warning others that it is malicious, then wait to see whether the attacker responds

  4. D

    Immediately reset all employee domain passwords, because impersonation on a social networking site indicates the attacker already has internal network access

Show answer and explanation

Correct answer: A

Explanation

Impersonation on social networking sites is a common pretexting and phishing technique in social engineering. In this scenario, the strongest first action is to reduce user exposure and initiate takedown through the platform while preserving evidence. Most major social networking platforms provide reporting workflows specifically for impersonation or fake accounts, which is the correct operational path. From a security operations perspective, this also follows incident response best practices: identification, containment, evidence preservation, impact assessment, and user communication. If later investigation shows users clicked the link or entered credentials, the organization can escalate with targeted password resets, phishing analysis, mail or web proxy review, and broader compromise assessment. CEH candidates should recognize that not every social media impersonation event proves internal compromise; the immediate goal is to stop the social engineering attack efficiently and lawfully.

  • A. Correct.

    Correct. This is the most appropriate first response because it addresses both containment and evidence preservation. Reporting the fake profile through the platform’s established impersonation reporting mechanism is the proper path for takedown. At the same time, notifying affected employees reduces the chance they will click malicious links or disclose credentials. Preserving screenshots, profile URLs, message content, and timestamps supports incident response, legal review, and any follow-up with the platform or law enforcement. This aligns with standard incident handling practice: contain the threat, preserve evidence, and notify impacted users.

  • B. Incorrect.

    Incorrect. Creating another fake profile may violate platform terms, complicate legal and ethical boundaries, and risk escalating the situation. In an authorized assessment or real incident, defenders should use approved reporting and incident response procedures rather than engaging in deceptive countermeasures on the platform. Although gathering intelligence is valuable, it should not delay containment of an active impersonation campaign targeting employees.

  • C. Incorrect.

    Incorrect. Publicly commenting can increase visibility of the fake profile, alert the attacker, and potentially expose employees or the organization to reputational issues. It is also unreliable, because the attacker can delete comments or block users. Internal notification and formal platform reporting are more effective and controlled methods for reducing risk. This option reflects the misconception that public confrontation is a good first step in social media incidents.

  • D. Incorrect.

    Incorrect. Password resets may be appropriate if there is evidence employees submitted credentials to the malicious portal, but impersonation alone does not prove compromise of internal accounts or network access. Resetting all domain passwords immediately is a broad action not justified by the facts given. The first priority is to stop employee interaction with the fraudulent profile, preserve evidence, and assess whether any credential theft actually occurred.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam