Exam 312-50v13 Topic 1 Question 438 Discussion
Actual exam question for ECCouncil's 312-50v13 exam
Question #: 438
Topic #: 1
Question #: 438
Topic #: 1
During a cybersecurity awareness drill at Quantum Analytics in San Francisco, California, the ethical hacking team tests the company's defenses against social media-based threats. Nadia creates a fake LinkedIn profile posing as a senior HR manager from Quantum Analytics, using a stolen company logo and publicly available employee details. Nadia sends connection requests to several employees, including data analyst Priya Sharma, inviting them to join a private group called Quantum Analytics Innovation Hub. The group's page prompts members to share their work email and department role for exclusive project updates.
What social engineering threat to corporate networks is Nadia's exercise primarily simulating?
What social engineering threat to corporate networks is Nadia's exercise primarily simulating?
Suggested Answer: C Vote an answer
This scenario most closely matches spam and phishing delivered through social networking platforms, a technique emphasized in CEH social engineering coverage as social media phishing or spear phishing via professional networks. Nadia impersonates a trusted internal authority figure, a senior HR manager, and uses believable branding elements such as a stolen logo and accurate employee details to establish credibility. She then initiates contact through connection requests and funnels targets into a controlled space, a private group, where she requests sensitive information. Collecting a work email address and department role may appear harmless, but CEH guidance notes that attackers often start with small, plausible requests to build trust and assemble data for deeper compromise. Work emails and roles enable targeted spear phishing, business email compromise preparation, password reset targeting, and crafting convincing pretexts aligned to the victim's function.
The core mechanics align with phishing: deception, impersonation, and a call to action designed to extract information. The "exclusive project updates" hook is a classic lure used to increase compliance. While the exercise could lead to involuntary data leakage as a downstream effect, the primary simulated threat is the phishing process itself, using social media as the delivery channel. Loss of productivity is not the intent here, and network vulnerability exploitation refers to technical system flaws rather than manipulating human trust.
Therefore, the most accurate classification of Nadia's drill is spam and phishing conducted through a social media pretext.
The core mechanics align with phishing: deception, impersonation, and a call to action designed to extract information. The "exclusive project updates" hook is a classic lure used to increase compliance. While the exercise could lead to involuntary data leakage as a downstream effect, the primary simulated threat is the phishing process itself, using social media as the delivery channel. Loss of productivity is not the intent here, and network vulnerability exploitation refers to technical system flaws rather than manipulating human trust.
Therefore, the most accurate classification of Nadia's drill is spam and phishing conducted through a social media pretext.
by Thieukedonders at Apr 28, 2026, 06:33 AM
0
0
0
10
Comments
Thieukedonders
2026-04-28 06:33:56Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).