312-50 Question 219
Single answer▪ Impersonation on Social Networking SitesDuring an authorized social engineering assessment, a CEH is asked to evaluate how vulnerable a company is to impersonation attacks on social networking sites. The rules of engagement prohibit sending malware, requesting credentials, or contacting customers directly. The tester wants to demonstrate a realistic impersonation risk using a fake profile that resembles a senior HR manager on a professional networking platform. Which action is the MOST appropriate and ethically compliant way to validate the risk while staying within scope?
- A
Create the look-alike profile, connect with a limited number of internal employees, and measure acceptance rates without asking for sensitive information
- B
Create the fake profile and send employees a link to a cloned single sign-on portal to measure who attempts to log in
- C
Register a domain similar to the company name and email employees from the fake HR manager account requesting tax forms
- D
Use the fake profile to message customers and business partners to see whether they will disclose confidential company plans
Show answer and explanation
Correct answer: A
Explanation
The best answer is to perform the least invasive action that still validates the specific risk under the rules of engagement. In this scenario, the objective is to assess impersonation on social networking sites, not credential theft, malware delivery, or external-party targeting. Creating a controlled look-alike profile and measuring whether employees accept connection requests from an impersonated executive or HR persona is a realistic and ethical way to demonstrate exposure. This aligns with standard penetration testing and social engineering best practices: stay within written authorization, minimize impact, avoid unnecessary data collection, and test only what has been approved. CEH-relevant reasoning emphasizes scope control, documentation of pretexts, and proving risk with measurable outcomes such as connection acceptance rate, message response rate, or trust indicators. Platform providers such as LinkedIn and other major social networks generally prohibit impersonation in their terms, so such testing should only be conducted under explicit written authorization and with tightly controlled safeguards. A final report should recommend mitigations such as employee awareness training, executive profile verification where available, reporting fake accounts promptly, limiting public exposure of organizational charts, and establishing procedures for validating unusual requests received through social platforms.
- A. Correct.
Correct. This approach directly tests susceptibility to social-network impersonation while remaining within the stated rules of engagement. It demonstrates whether employees trust and engage with a convincing impostor profile, but it avoids collecting credentials, distributing malware, or contacting prohibited external parties. Measuring connection acceptance or profile engagement is a common low-impact way to validate social engineering exposure.
- B. Incorrect.
Incorrect. Although this would measure the impact of impersonation, sending users to a cloned login page crosses the stated boundary against requesting credentials. Even if the intent is only to measure attempts, it introduces credential-harvesting behavior that is specifically out of scope.
- C. Incorrect.
Incorrect. This combines impersonation with email-based phishing and requests for sensitive documents, which exceeds the allowed test boundaries. Requesting tax forms is a high-risk action that could cause operational and legal issues and is not necessary to prove the social-network impersonation weakness.
- D. Incorrect.
Incorrect. The scenario explicitly prohibits contacting customers directly. Messaging customers or partners also expands the test beyond internal employee exposure and creates unnecessary reputational and legal risk.