312-50 exam dumps

312-50 practice question 49 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 49

Single answer▪ Footprinting through Social Engineering

During an authorized CEH assessment, you are limited to passive reconnaissance and non-intrusive social engineering to gather information about a target company's internal technology stack. The rules of engagement allow pretexting phone calls to publicly reachable staff but prohibit requesting passwords, MFA codes, or any action that changes systems. Which approach is the MOST appropriate and effective for footprinting through social engineering while staying within scope?

  1. A

    Call the help desk while posing as a new remote employee and ask which VPN client, ticketing portal, and remote support tools are used so you can prepare your laptop before orientation

  2. B

    Email several employees a link to a cloned SSO login page and record who attempts to authenticate so you can identify the identity provider in use

  3. C

    Call the network administrator and ask them to read the current firewall rule set over the phone because you are updating asset inventory documentation

  4. D

    Message employees on social media asking them to send a screenshot of the corporate intranet home page so you can identify internal applications

Show answer and explanation

Correct answer: A

Explanation

In CEH-style reconnaissance, footprinting through social engineering is about eliciting useful organizational and technical information without crossing into credential theft, unauthorized access, or excessive collection of sensitive internal data. Pretexting a plausible operational need, such as onboarding, vendor coordination, or remote access preparation, is commonly used to learn about technologies, departments, naming conventions, support workflows, and externally exposed services. The best choice is the help-desk pretext because it gathers actionable reconnaissance data while respecting the engagement constraint of non-intrusive information gathering. By contrast, phishing with a cloned login page is an active credential-harvesting technique, not passive footprinting. Requesting firewall rules or intranet screenshots seeks highly sensitive internal information and is disproportionate to a footprinting objective. This aligns with standard penetration testing best practices: stay within the rules of engagement, use the least intrusive method necessary, and avoid collecting credentials or sensitive internal artifacts unless explicitly authorized.

  • A. Correct.

    Correct. This is a classic pretexting-based footprinting technique that aligns with passive/non-intrusive social engineering when properly authorized. It focuses on collecting high-value environmental details such as VPN software, support tooling, and ticketing platforms without asking for credentials or causing system changes. These details help map the target's technology stack and potential attack surface while remaining within the stated rules of engagement.

  • B. Incorrect.

    Incorrect. Sending a link to a cloned login page is phishing intended to capture authentication behavior and potentially credentials. Even if the goal is only to identify the identity provider, this is intrusive and creates unnecessary risk. It also violates the stated scope because it involves deceptive credential harvesting infrastructure rather than simple information gathering.

  • C. Incorrect.

    Incorrect. Asking for a firewall rule set goes beyond normal footprinting and requests sensitive internal security configuration data that staff would not reasonably disclose in a benign pretext. It is also far more likely to trigger suspicion and may exceed a non-intrusive social engineering objective. Effective footprinting typically seeks indirect environmental clues, not detailed defensive configurations.

  • D. Incorrect.

    Incorrect. Requesting screenshots of the internal intranet asks employees to disclose internal content that may contain confidential information. This is more invasive than necessary for initial footprinting and can expose sensitive data unintentionally. Social engineering for footprinting should minimize data collection and avoid soliciting internal documents or images when lower-risk methods can obtain sufficient intelligence.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam