312-50 Question 31
Select 2▪ Footprinting through Social Networking SitesDuring a sanctioned reconnaissance phase, you are asked to gather information about a target organization without directly interacting with its systems or employees. While reviewing employees' public social networking profiles, you want to identify details that would most effectively support later password-guessing and spear-phishing simulations. Which TWO findings would be the most valuable for that purpose?
- A
Several employees publicly post photos of badges showing the company logo and partial office floor layouts in the background
- B
Multiple employees list their job titles, current projects, team names, manager names, and use a consistent corporate email naming pattern in their profiles
- C
A former employee writes a public post criticizing management and discussing long working hours
- D
Employees frequently share public posts about pet names, birthdays, anniversaries, favorite sports teams, and "fun facts" used in workplace introductions
- E
An employee's profile shows that they follow several cybersecurity vendors and industry news accounts
Show answer and explanation
Correct answers: B, D
Explanation
The best answers are options 2 and 4 because they provide the most actionable intelligence for two specific follow-on activities: spear-phishing simulation and password profiling. In CEH-style reconnaissance, footprinting through social networking sites focuses on collecting publicly exposed organizational and personal data that can be used to map people, roles, naming conventions, business context, and likely password themes. Organizational details such as job titles, projects, managers, and email patterns improve phishing realism by helping an assessor mimic internal communication. Personal details such as pet names, birthdays, and favorite teams commonly appear in weak passwords or password reset clues. This aligns with widely recognized security awareness guidance from sources such as NIST's recommendations on digital identity and authentication hygiene, which emphasize avoiding guessable secrets and reducing exposure of personal information that can support social engineering. The scenario also reflects best practice in ethical hacking: passive reconnaissance using publicly available information without directly contacting targets or interacting with systems.
- A. Incorrect.
This is useful for general reconnaissance and could support physical security assessments, but it is less directly valuable than other findings for password-guessing and spear-phishing. Badge images and office details may help with impersonation or onsite social engineering, yet they do not provide the strongest input for crafting personalized phishing lures or generating likely password candidates compared with personal trivia and organizational context.
- B. Correct.
Correct. Publicly available job titles, project names, team structures, manager names, and a consistent email naming convention are highly valuable for spear-phishing. They allow an ethical hacker to build realistic phishing pretexts, address targets credibly, and derive probable email addresses for simulation campaigns. This is a classic example of footprinting through social networking sites to map relationships and communication patterns without active engagement.
- C. Incorrect.
This may indicate employee dissatisfaction and could be relevant to broader social engineering risk, but by itself it is not as strong for password-guessing or targeted phishing as detailed organizational information or personal trivia. A tester might note it as contextual intelligence, but it does not directly provide the best material for crafting convincing credential attacks.
- D. Correct.
Correct. Publicly shared personal details such as pet names, birthdays, anniversaries, sports teams, and workplace icebreaker facts are common ingredients in weak passwords and security question answers. They also help personalize phishing messages. In social-network-based footprinting, this kind of overshared personal information is especially useful for password profiling and for building believable pretexts tailored to specific employees.
- E. Incorrect.
Following cybersecurity vendors or news accounts may reveal professional interests, but it does not strongly support password-guessing or realistic spear-phishing compared with the other options. A candidate might choose this because it appears security-related, but it is a weak indicator for the stated objective.