312-50 exam dumps

312-50 practice question 32 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 32

Select 3▪ Footprinting through Social Networking Sites

During an authorized reconnaissance phase of a CEH assessment, you are asked to gather information about a target company's employees by using only publicly accessible social networking data. The client specifically wants to understand what information an attacker could realistically collect to prepare convincing spear-phishing emails without directly contacting employees or attempting to bypass any privacy controls. Which TWO actions would be the most appropriate and effective for this purpose?

  1. A

    Review employees' public LinkedIn profiles to identify job roles, reporting lines, technologies mentioned in experience sections, and naming conventions used in company email addresses shared in posts or resumes.

  2. B

    Create a fake recruiter account and send connection requests to employees to gain access to private profile details and restricted contact information.

  3. C

    Examine public posts on platforms such as LinkedIn, X, Facebook, or Instagram for references to projects, office events, travel, vendors, and internal tools that could be used to craft believable pretexts.

  4. D

    Use password-reset functions on social networking platforms to determine whether specific employee accounts exist and to infer their personal email addresses.

  5. E

    Search public employee social media photos and profile metadata for visible badges, office locations, whiteboards, conference attendance, and geotags that reveal organizational details.

Show answer and explanation

Correct answers: A, C, E

Explanation

This question tests the CEH candidate's ability to distinguish passive social-network footprinting from active social engineering or account-enumeration techniques. In an authorized reconnaissance engagement limited to publicly accessible information, the best choices are the actions that collect OSINT from openly available social networking content without interacting with employees or circumventing privacy settings. Public professional profiles, posts, and images commonly reveal names, titles, technologies, partners, travel, and physical security details that can support spear-phishing pretexts. By contrast, fake personas and password-reset probing go beyond passive footprinting and may violate the stated rules of engagement. This aligns with standard ethical hacking practice: stay within scope, use only authorized methods, and prefer passive reconnaissance when the client requests an assessment of exposed information. Relevant best practices are consistent with OSINT methodology and common social engineering guidance, including reviewing only public data sources, documenting source context, and avoiding unauthorized access or deceptive engagement unless explicitly approved in the rules of engagement.

  • A. Correct.

    Correct. Public LinkedIn profiles are a common and legitimate source for footprinting through social networking sites. They can reveal organizational structure, employee responsibilities, technologies in use, business units, and sometimes clues about email naming patterns when employees publish contact details in resumes, portfolios, or posts. This information is highly valuable for building realistic spear-phishing scenarios during an authorized assessment.

  • B. Incorrect.

    Incorrect. Creating a fake recruiter persona and sending deceptive connection requests moves beyond passive footprinting into social engineering. The scenario explicitly limits the tester to publicly accessible data and prohibits direct interaction with employees or bypassing privacy controls. Although attackers may use this tactic in the real world, it is not appropriate for the stated engagement constraints.

  • C. Correct.

    Correct. Public social posts often expose operational details such as project names, third-party vendors, internal collaboration tools, conference participation, travel plans, and office events. Attackers routinely use these details to make phishing messages appear timely and credible. This is a practical and ethical OSINT approach when restricted to publicly visible content.

  • D. Incorrect.

    Incorrect. Using password-reset workflows to enumerate accounts is not passive collection from social networking content. It may interact with platform security mechanisms and can cross legal or scope boundaries, especially if it attempts to infer nonpublic account data. In this scenario, the goal is to gather information from public social networking data only, not to test platform account recovery behavior.

  • E. Correct.

    Correct. Publicly posted images can reveal significant intelligence, including office layout, employee badges, whiteboards, equipment, conference lanyards, location data, and business travel patterns. Geotags and visual artifacts are well-known OSINT sources and can help an attacker craft targeted lures or understand the target environment without contacting anyone directly.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam