Exam 312-50v13 Topic 1 Question 438 Discussion

Actual exam question for ECCouncil's 312-50v13 exam
Question #: 438
Topic #: 1
During a cybersecurity awareness drill at Quantum Analytics in San Francisco, California, the ethical hacking team tests the company's defenses against social media-based threats. Nadia creates a fake LinkedIn profile posing as a senior HR manager from Quantum Analytics, using a stolen company logo and publicly available employee details. Nadia sends connection requests to several employees, including data analyst Priya Sharma, inviting them to join a private group called Quantum Analytics Innovation Hub. The group's page prompts members to share their work email and department role for exclusive project updates.
What social engineering threat to corporate networks is Nadia's exercise primarily simulating?

Suggested Answer: C Vote an answer

This scenario most closely matches spam and phishing delivered through social networking platforms, a technique emphasized in CEH social engineering coverage as social media phishing or spear phishing via professional networks. Nadia impersonates a trusted internal authority figure, a senior HR manager, and uses believable branding elements such as a stolen logo and accurate employee details to establish credibility. She then initiates contact through connection requests and funnels targets into a controlled space, a private group, where she requests sensitive information. Collecting a work email address and department role may appear harmless, but CEH guidance notes that attackers often start with small, plausible requests to build trust and assemble data for deeper compromise. Work emails and roles enable targeted spear phishing, business email compromise preparation, password reset targeting, and crafting convincing pretexts aligned to the victim's function.
The core mechanics align with phishing: deception, impersonation, and a call to action designed to extract information. The "exclusive project updates" hook is a classic lure used to increase compliance. While the exercise could lead to involuntary data leakage as a downstream effect, the primary simulated threat is the phishing process itself, using social media as the delivery channel. Loss of productivity is not the intent here, and network vulnerability exploitation refers to technical system flaws rather than manipulating human trust.
Therefore, the most accurate classification of Nadia's drill is spam and phishing conducted through a social media pretext.

by Thieukedonders at Apr 28, 2026, 06:33 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
Thieukedonders
2026-04-28 06:33:56
Selected Answer: B
The scenario emphasizes that employees are submitting internal information (work email, department role) without realizing the risk — no fake login page, no direct credential theft, no malicious link. The outcome being tested is data leakage through social manipulation, not phishing in the classical CEH sense.
upvoted 2 times
...
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10