312-50 Question 218
Single answer▪ Impersonation on Social Networking SitesDuring an authorized social engineering assessment, a CEH tester is asked to evaluate how vulnerable a company is to employee-targeted scams on professional social networking platforms. The rules of engagement prohibit contacting real customers, collecting credentials, or causing reputational harm to the client. The tester considers several approaches involving impersonation on a social networking site. Which approach is the MOST appropriate and ethically compliant for this assessment?
- A
Create a clearly controlled look-alike profile that mimics a generic recruiter in the client's industry, avoid using any real employee names or customer identities, and use it only to measure whether employees accept connection requests and disclose non-sensitive organizational details
- B
Clone the CEO's real social networking profile, copy their photos and employment history exactly, and send urgent messages to employees asking them to open an external document so the tester can measure click-through behavior
- C
Register an account using a real customer's name and logo to make connection requests appear trustworthy, because external brand impersonation is less likely to harm the client directly
- D
Create multiple fake employee profiles and publicly post misleading statements about layoffs and security incidents to see how quickly staff react and report the activity
Show answer and explanation
Correct answer: A
Explanation
In CEH-relevant social engineering engagements, impersonation on social networking sites must be carefully constrained by scope, legality, and ethics. Real attackers often clone executives, recruiters, coworkers, or trusted brands to build credibility, but an authorized tester should choose the least harmful method that still answers the client's security question. In this scenario, the safest valid approach is a controlled pretext that does not misuse a real person's identity and does not attempt credential theft, malware delivery, or public deception. This reflects standard penetration testing and social engineering best practices: obtain written authorization, define rules of engagement, minimize impact, avoid third-party harm, and measure only agreed outcomes. Industry guidance such as PTES-style scoping principles and common red-team/social-engineering engagement standards emphasize authorization, proportionality, and limiting collateral effects. The key applied concept is that social-network impersonation can be tested without actually cloning a real executive, customer, or employee when the objective is to assess employee trust and reporting behavior rather than maximize deception at any cost.
- A. Correct.
Correct. This option aligns best with ethical testing principles and common social engineering rules of engagement. It uses a controlled pretext without impersonating a real person, avoids harvesting credentials, and limits the objective to measuring exposure such as trust in unsolicited connection requests and low-risk information disclosure. This is consistent with minimizing harm while still evaluating susceptibility to impersonation-based attacks on social networking platforms.
- B. Incorrect.
Incorrect. Although cloning an executive profile is a realistic attacker technique, this option violates the scenario constraints. It impersonates a real individual, uses their identity and likeness, and attempts to induce risky behavior through an external document. That introduces unnecessary reputational and operational risk and goes beyond a minimally invasive assessment.
- C. Incorrect.
Incorrect. Using a real customer's identity and brand is not ethically appropriate and can create legal and reputational consequences for both the client and the third party. The fact that the impersonated entity is external does not make it acceptable. Authorized assessments should avoid unauthorized use of real identities unless explicitly approved and tightly controlled, which is not the case here.
- D. Incorrect.
Incorrect. Creating fake employee accounts and posting false public claims about layoffs or security incidents is likely to cause reputational harm, internal panic, and possibly business disruption. The scenario explicitly prohibits causing reputational harm, so this approach is outside acceptable engagement boundaries even if it might generate measurable reactions.