nerdexam
EC-Council

312-50V11 · Question #703

You are tasked to perform a penetration test. While you are performing information gathering, you find an employee list in Google. You find the receptionist's email, and you send her an email changing

The correct answer is A. Social engineering. The attack described uses social engineering by psychologically manipulating the receptionist through email impersonation and deception to gain network access.

Social Engineering

Question

You are tasked to perform a penetration test. While you are performing information gathering, you find an employee list in Google. You find the receptionist's email, and you send her an email changing the source email to her boss's email (boss@company). In this email, you ask for a pdf with information. She reads your email and sends back a pdf with links. You exchange the pdf links with your malicious links (these links contain malware) and send back the modified pdf, saying that the links don't work. She reads your email, opens the links, and her machine gets infected. You now have access to the company network. What testing method did you use?

Options

  • ASocial engineering
  • BPiggybacking
  • CTailgating
  • DEavesdropping

How the community answered

(53 responses)
  • A
    79% (42)
  • B
    4% (2)
  • C
    13% (7)
  • D
    4% (2)

Why each option

The attack described uses social engineering by psychologically manipulating the receptionist through email impersonation and deception to gain network access.

ASocial engineeringCorrect

Social engineering exploits human psychology rather than technical vulnerabilities to gain unauthorized access or information. In this scenario, the attacker impersonated a trusted authority figure (the boss) via email spoofing, manipulated the receptionist into sharing a document, then weaponized that document and used trust to get the victim to open malicious links. Every step relied on deceiving a person rather than exploiting a software flaw.

BPiggybacking

Piggybacking is a physical security attack where an unauthorized person gains building access with the consent of an authorized person, which did not occur here.

CTailgating

Tailgating is also a physical access technique where an attacker follows an authorized person through a secured door without their knowledge, not applicable to this email-based scenario.

DEavesdropping

Eavesdropping involves intercepting communications passively to gather information, whereas this attack involved active deception and interaction with the victim.

Concept tested: Social engineering via email impersonation and phishing

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#email spoofing#spear phishing#malware delivery#social engineering

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice