312-50 exam dumps

312-50 practice question 33 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 33

Select 2▪ Footprinting through Social Networking Sites

During an authorized reconnaissance phase, a CEH professional is asked to gather intelligence about a target organization's likely technologies, third-party relationships, and personnel naming conventions by using only publicly available information from social networking sites. Which TWO actions would provide the most useful footprinting data while staying within passive OSINT practices?

  1. A

    Review employees' LinkedIn profiles and posts to identify job titles, technology stacks, certifications, and references to vendors or cloud platforms

  2. B

    Create a fake recruiter account and directly message employees to ask what VPN and endpoint protection products the company uses

  3. C

    Examine public posts on X, GitHub, and other professional social platforms for screenshots, project references, email formats, and conference announcements tied to the organization

  4. D

    Use a password spraying attack against employees' social media accounts to verify whether reused corporate credentials are exposed

Show answer and explanation

Correct answers: A, C

Explanation

The best answers are 1 and 3 because the scenario specifically requires passive intelligence gathering from public social-networking sources. In CEH-style reconnaissance, social networking sites are commonly used to identify employee roles, organizational structure, technologies, partners, office locations, naming conventions, and potential attack paths without touching the target's infrastructure or contacting personnel. LinkedIn is especially valuable for role and technology inference, while platforms such as X, GitHub, conference pages, and other public professional communities can expose screenshots, project details, email patterns, and business relationships. By contrast, impersonating a recruiter to message employees is social engineering with active engagement, and password spraying is an active attack technique rather than passive footprinting. This distinction is consistent with standard ethical hacking methodology and rules-of-engagement principles used in professional assessments: passive OSINT relies on publicly accessible data, while active collection and social engineering require explicit authorization and separate scoping.

  • A. Correct.

    Correct. Public LinkedIn profiles and related posts are a classic source of passive footprinting data. Employees often disclose their roles, certifications, tools they use, cloud migrations, security products, and business partners. This can help an ethical hacker infer technologies in use, identify likely administrators, and derive naming conventions such as first.last or first initial plus surname from visible profile URLs and contact patterns.

  • B. Incorrect.

    Incorrect. Although social engineering is covered in CEH, this action is not passive footprinting because it involves direct interaction and deception to elicit information. In a scenario restricted to passive OSINT through social networking sites, creating a fake persona and contacting employees exceeds the stated scope and changes the engagement type.

  • C. Correct.

    Correct. Public content across X, GitHub, conference platforms, and similar sites can reveal valuable footprinting details without interacting with the target. Screenshots may expose internal hostnames, collaboration tools, badge designs, or operating systems; code repositories may reveal email naming patterns or technology choices; conference announcements can identify teams, projects, and third-party relationships. This aligns with passive reconnaissance best practices.

  • D. Incorrect.

    Incorrect. Password spraying is an active attack, not footprinting through social networking sites. It attempts authentication against accounts and could disrupt services or violate the rules of engagement if not explicitly authorized. The misconception is that any information-gathering activity counts as reconnaissance, but CEH distinguishes passive OSINT from active enumeration and attacks.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam