Skip to content
ScopefileGet the app

Module 9Domain 4 of 9Network and Perimeter Hacking

Social engineering: attacks on people, defenses for people

Social engineering, CEH Module 9, covers attacks aimed at people: the phishing family, impersonation in person and on social networks, insider threats and identity theft, plus the controls that stop each one. Trust, habit and haste are the weaknesses here, so the defenses are verification procedures, training, physical barriers and monitoring that hold up when one person gets fooled.

Exam
312-50
Domain
4 of 9
Domain weight
24%
This file
~5%
Targets
15

Four passes over a social engineering scenario

  1. Name the channel

    Email, a voice call, a text message, a website, a social network profile or a person at a door. The channel alone narrows the term to two or three candidates; the full term-by-channel grid lives on the social engineering attack types file.
  2. Name what was being sought

    A password, a payment, an unescorted walk into a building, or data the person could already reach. The objective is what separates identity theft from impersonation, and an insider case from an outside one.
  3. Name the human lever

    A social engineering scenario usually turns on one: respect for a title, a deadline, curiosity, or fear of a penalty. Once you have named it, you know which procedure or training message would have broken the chain.
  4. Name the control layer

    Administrative (policy, training, verification procedures), technical (filtering, strong authentication, monitoring) or physical (entry control, shredding). Where two controls both apply, the stronger one acts on the specific lever from pass three.

Module vocabulary beyond the phishing family

Human-based technique
Deception carried out in person or by voice, such as posing as staff or watching someone enter a PIN. It relies on courtesy and on employees who were never told they may refuse.
Computer-based technique
Deception delivered through email, websites, pop-ups or chat. It relies on users trusting whatever a screen shows them.
Mobile-based technique
Deception through text messages, repackaged apps or fake store listings. It relies on small screens that hide sender details and link targets.
Insider threat
Harm caused by someone with legitimate access: an employee, contractor or partner. It relies on trust the organization already granted, which is why perimeter devices never see it.
Negligent insider
An insider who causes a breach through carelessness, such as mishandling records, with no intent to harm.
Malicious insider
An insider who deliberately steals, sabotages or leaks, often while disgruntled or on the way out.
Compromised insider
A legitimate account under an outsider's control. The activity looks internal because the credentials are real.
Impersonation on social networks
A fake profile built from a real person's or company's public details, used to collect connections and trust. It relies on platforms that do not verify who opened an account.
Identity theft
Using another person's identifying information to open accounts, obtain services or commit fraud in their name. It relies on exposed personal records.
Deepfake impersonation
Synthetic voice or video of a real person, which the v13 course outline lists under impersonation. It relies on staff accepting a familiar voice or face as proof of identity.

What a defender sees, and what stops it

Social engineering leaves thin technical evidence, because the victim acts with valid rights. The trace is usually something a person noticed (an analyst, a help desk lead, a guard) rather than an exploit in a log.

Signals by channel

  • Email: a gateway flag on a lookalike sender domain, a display name that does not match the address, or link text that differs from its target. MITRE ATT&CK covers these under Phishing (T1566) and Phishing for Information (T1598), with detection and mitigation notes for each.
  • Voice and text: a burst of help desk tickets asking for password or MFA resets, callers who cannot pass verification but keep raising the urgency, or SMS lures that staff forward to the security mailbox.
  • Physical: badge logs that record one entry while the camera shows two people, unescorted visitors in restricted areas, sensitive paper in general waste.
  • Social networks: a new profile reusing an executive's photo and title, or a wave of connection requests to staff from a self-described recruiter.
  • Insider activity: access outside a person's role, bulk downloads close to a resignation date, off-hours logins, removable media where policy forbids it. User and entity behavior analytics (UEBA) and log review are built to catch these, while perimeter devices see nothing unusual.

Controls matched to each threat

  • Pretexting and phone impersonation: a written procedure for any request to reset, disclose or pay, a call-back to a number already on file, and explicit permission for staff to refuse.
  • Tailgating and piggybacking: mantraps, turnstiles, a one-badge-one-person rule, and guards trained to challenge.
  • Dumpster diving: a clean-desk policy, cross-cut shredding, and sanitizing media before disposal.
  • Email lures: SPF, DKIM and DMARC on your own domains so exact-domain spoofing fails, attachment sandboxing and link rewriting at the gateway, and a one-click report button.
  • Insider threats: separation of duties, job rotation and mandatory vacation, same-day access removal at exit, and monitoring under a published acceptable-use policy.
  • Social-network impersonation and identity theft: a policy on what staff post about their work, monitoring for profiles that copy executives, a takedown route with each platform, and minimal collection of personal records.

Pairs that get confused

Impersonation against identity theft. Impersonation borrows someone's identity to steer a conversation; identity theft uses their personal data to transact as them. A loan opened in an employee's name is identity theft even if nobody ever spoke to anyone.

Compromised insider against malicious insider. Both show internal activity on a real account. The clue is whether the account owner knew: intent sits with the employee in the malicious case and with an outsider in the compromised one.

Reverse social engineering against quid pro quo. In quid pro quo the attacker opens with an offer. In reverse social engineering the attacker arranges a problem and waits for the target to come asking for help, which makes the victim the one who initiates contact.

Authorization for tests that target people

Phishing simulations and pretext calls fall under the same rules of engagement covered in Module 1 as any other assessment. A sound scope names the roles in play, the pretexts that are off-limits (posing as law enforcement, exploiting personal hardship), how any collected credentials are stored and destroyed, who on the client side knows the test is live, and when it stops. The report describes patterns and training gaps; singling out individual employees falls outside an ethical write-up.

Run the four passes

Each target is a short situation. Run channel, objective, lever and control layer in that order, and let the debrief show which pass a miss skipped.

Answered 0/15Hits 0

T-01

An organization wants to mitigate the risk of targeted spear-phishing attacks leading to credential theft. Which layered defense strategy provides the MOST comprehensive protection?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: training helps users recognize targeted lures, while MFA stops a stolen password alone from granting access, covering both the human and credential layers.
  2. BFirewalls and EDR help against malware, but a convincing phishing page that harvests credentials can bypass both.
  3. CSegmentation limits lateral movement after a compromise but does not stop credentials from being phished in the first place.
  4. DComplexity and rotation rules do not help once a user types the password into a phishing page, and frequent rotation encourages weaker patterns.
T-02

An organization recently deployed a comprehensive DLP solution to prevent data exfiltration and is considering relaxing its rigid RBAC policies to reduce administrative overhead. Which architectural principle highlights the primary risk of this approach?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: DLP detects and blocks some data movement, but least privilege limits who can reach data at all; weakening RBAC widens access that DLP may not catch.
  2. BRBAC enforces access by role and does not depend on DLP payload inspection; the two controls work independently.
  3. CAccess reviews remain essential with DLP in place because DLP does not decide who should hold which permissions.
  4. DModern DLP covers data in motion, at rest and in use, so this claim is inaccurate and misses the real risk.
T-03

An attacker disguises as a trusted vendor and sends an email to an employee requesting a login password to 'verify security settings.' What type of social engineering attack does this represent?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AQuid pro quo offers a service or reward in exchange for information, such as fake tech support, rather than a simple impersonated request.
  2. BCorrect: impersonating a trusted vendor by email to trick an employee into revealing a password is phishing.
  3. CBaiting lures victims with something enticing, such as an infected USB drive or a free download, rather than a direct credential request.
  4. DTailgating is physical, following an authorized person through a secured door, not an email deception.
T-04

A CISO is reviewing the quarterly security awareness board report. Which metric most accurately demonstrates a measurable reduction in organizational risk against social engineering?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: faster reporting of suspicious emails shows staff actively detecting attacks and shortens the window for responders, which directly reduces risk.
  2. BGateway block counts measure the email filter's performance and attack volume, not human resilience to social engineering.
  3. CCompletion rates show attendance at training, not whether behavior actually improved.
  4. DThe number of simulations sent measures program activity, not whether employees resist or report attacks.
T-05

An organization's finance director receives an urgent email requesting payment for an unexpected invoice. The email originates from a known vendor's domain, and SPF, DKIM, and DMARC checks pass. Which indicator is the strongest evidence of a Business Email Compromise (BEC) attack?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASpelling errors are a common phishing sign, but carefully written BEC messages, especially from a compromised real vendor account, often lack them.
  2. BCorrect: when authentication passes, the attacker likely controls the vendor's real account, so contextual anomalies like an unexpected, urgent invoice are the strongest signal.
  3. CMany legitimate businesses send through third-party email platforms, so this routing is not reliable evidence of fraud.
  4. DThe stem says DMARC checks pass, and a missing enforcement policy would reflect sender configuration rather than proof of compromise.
T-06

Which element of an IT infrastructure is most threatened by phishing attacks, social engineering, and keylogging techniques?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: phishing, social engineering and keyloggers all aim to steal usernames and passwords, the access credentials attackers use to get in.
  2. BNetwork hardware is attacked through misconfiguration or firmware flaws, not primarily through phishing or keylogging.
  3. CPeripheral devices may host hardware keyloggers, but they are the means, not the asset these techniques ultimately target.
  4. DServer uptime is threatened by DoS attacks and failures, not by techniques aimed at capturing user input.
T-07

A malicious actor has been observing the online behavior of the CFO of a large financial firm, identifying the frequently visited forums and Q&A websites. After confirming some of these sites are insecure, the attacker plants malware to collect the CFO's login details. Which kind of attack does this scenario exemplify?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACookie or session poisoning tampers with session data to impersonate users, not compromising websites the target visits.
  2. BCross-site scripting is a web flaw that might be used on a compromised site, but the overall targeted strategy has a more specific name.
  3. CCross-site request forgery tricks a logged-in browser into submitting unwanted requests, not planting malware on frequented sites.
  4. DCorrect: a watering hole attack compromises sites a specific target is known to visit and waits for them to come, much like a predator at a watering hole.
T-08

Given the rise of phishing scams targeting employees, what is an effective countermeasure to mitigate these attacks within an organization?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: training employees to recognize and report phishing addresses the human element these attacks exploit, especially alongside technical filtering.
  2. BAntivirus may catch malicious attachments, but it does not stop users from entering credentials on a fake website.
  3. CFirewalls filter network traffic but do not evaluate the deceptive content of an email.
  4. DSegmentation limits damage after a compromise but does not prevent employees from falling for phishing.
T-09

To prevent unauthorized access to an organization's systems through social engineering, enhancing employee verification measures is crucial. Which of the following options best improves employee verification?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASingle sign-on streamlines access but makes one credential unlock many systems, so it does not strengthen verification by itself.
  2. BComplex passwords resist guessing but are still handed over in social engineering attacks, so they do not add a verification factor.
  3. CCorrect: MFA requires an additional factor beyond the password, so credentials obtained through social engineering are not enough on their own.
  4. DGuest Wi-Fi provides network access for visitors and has nothing to do with verifying employee identity.
T-10

In the context of social engineering, which of the following is NOT a method used to manipulate a target into divulging sensitive information?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABaiting manipulates victims with an enticing item, such as a free download or found USB drive, to trigger an infection or disclosure.
  2. BCorrect: DNS spoofing manipulates name resolution data to redirect traffic, which is a technical network attack rather than manipulation of a person.
  3. CPhishing uses deceptive messages to persuade people to reveal information, a core social engineering method.
  4. DPretexting invents a believable scenario to gain a target's trust and extract information, a core social engineering technique.
T-11

During a security awareness training session, an employee named Mike consistently follows instructions without questioning them. What does this imply?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: complying with instructions without questioning them makes a person susceptible to authority-based pretexts, a trait social engineers seek.
  2. BNothing about following instructions without question indicates that someone holds a physical security role.
  3. CCompliance in training does not indicate which department a person works in.
  4. DFollowing instructions says nothing about seniority, and senior staff are often targeted for different reasons.
T-12

You are conducting a social engineering attack on a high-security facility. In the first phase, you gather intelligence about the facility through online research and on-site observation. In the second phase, you identify a suitable target within the organization. What is the third phase of social engineering in this context?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AFollowing a target covertly is a surveillance tactic, not the recognized next phase after selecting a target.
  2. BExtracting information comes later, after trust is built, and rushing it tends to raise suspicion.
  3. CPhysical entry may be a goal, but it is not the standard third phase in the social engineering lifecycle.
  4. DCorrect: after researching the organization and selecting a target, the attacker develops a relationship and trust before exploiting it.
T-13

Jane is working at the customer support center of a large retail company. She receives an urgent call from a customer claiming that their credit card details were compromised and they need immediate assistance to secure their account. Of the following actions, which should Jane take?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: verifying identity through established procedures before acting, then escalating to security, prevents a social engineer from hijacking the account.
  2. BAsking customers to email card details exposes sensitive data over an insecure channel and violates payment security practice.
  3. CIssuing card details by phone to an unverified caller is exactly what a social engineer would hope for.
  4. DHanging up fails a potentially genuine customer; the right response is to verify and route the issue properly.
T-14

Before initiating a social engineering engagement, what is the essential preliminary step to ensure the engagement is both ethical and legally compliant?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATools can be acquired at any time; they do not make the engagement ethical or legal.
  2. BCorrect: written authorization and agreed rules of engagement define scope, methods and limits, making the test legal and ethical.
  3. CTraining improves skills but does not authorize testing a specific organization.
  4. DGathering open-source information is part of the engagement itself and should begin only after permission is granted.
T-15

A malicious actor is stealing sensitive data by posing as an internal IT support representative over the phone. Which technique is being employed?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASQL injection exploits unsanitized database queries in web applications, not phone-based impersonation.
  2. BPharming redirects users to fraudulent websites through DNS or host file manipulation, not phone calls.
  3. CBrute force systematically guesses passwords, with no human manipulation involved.
  4. DCorrect: impersonating IT support over the phone is social engineering, specifically vishing with a pretext, to manipulate employees into revealing data.

Every control in Module 9 does one of two jobs: it slows a request down, or it moves the request onto a channel the attacker does not own.

Edges of the module

Are insider threats really social engineering?

They share the module. Blueprint v5.0 (checked Oct 11, 2026) lists insider threats in Module 9 next to impersonation on social networks and identity theft. The common thread is misplaced trust: an insider already holds it, while an outside social engineer has to earn it.

Is it worth memorizing phishing tool names?

Rarely. The v13 course outline (checked Oct 11, 2026) mentions phishing tools, but the concepts in this module are defined by behavior and channel. Know that simulation platforms exist for awareness testing and spend the saved time on matching controls to threats.

Does v13 add AI material to this module?

Yes: EC-Council's v13 course outline (checked Oct 11, 2026) lists AI impersonation, including deepfakes, under Module 9. Treat it as a variant of impersonation. The defense is the same habit of confirming a request through a second, independent channel, applied to voice and video.

Why does social engineering also appear under footprinting?

Blueprint v5.0 (checked Oct 11, 2026) lists it inside Module 2, footprinting and reconnaissance, as an information source, and again here as an attack class with countermeasures. Revising one module reinforces the other.

Sources