Identify social engineering vectors and physical bypass techniques, then select the control that actually stops them: mantrap or turnstile for tailgating, callback verification for help desk impersonation, and log correlation for SMB anomalies. The key is matching the countermeasure to the specific attack.
Start practicing
Social Engineering and Physical Security — choose a session length
Free · No account required
Domain overview
This CEH domain covers human manipulation tactics and bypassing physical barriers, tested through scenario questions about phishing, pretexting, tailgating, and facility controls. You must identify attack types, choose effective countermeasures, and recognize indicators in logs or call transcripts. Expect incident-response style prompts rather than pure definitions.
Exam objectives
Phishing variants: spear phishing, vishing, whaling, and pharming target selection
Pretexting and impersonation calls to help desk for credential or MFA disclosure
Tailgating, piggybacking, and mantrap, turnstile, and badge-access countermeasures
SMB port 445, NTLM, and Kerberos anomalies indicating credential theft or lateral movement
Confusing tailgating with piggybacking, or picking awareness training as a physical control when the question asks for a physical barrier.
Treating SMB port 445 traffic from an unexpected internal subnet as normal file sharing instead of recognizing lateral movement or credential abuse.
Assuming a help desk should verify identity by asking for the password, when the correct control is callback verification or a shared secret.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A penetration tester is assessing an organization's physical security. The tester wants to gain unauthorized access to a secured server room that uses a biometric fingerprint scanner. Which of the following techniques would be MOST effective for bypassing the biometric scanner?
2During a social engineering engagement, a tester calls the help desk posing as an employee from the IT department. The tester claims to be working on a critical system update and needs the employee's password to proceed. Which type of social engineering attack is being executed?
3Which of the following is the BEST defense against tailgating attacks in a secure facility?
4An employee receives an email that appears to be from the CEO, asking the employee to urgently wire funds to a vendor. The email address is slightly misspelled. What type of social engineering attack is this?
5Refer to the exhibit. A security analyst runs ping and arp commands. What is the most likely attack occurring?
6You are a security consultant hired by a mid-sized company with 500 employees. The company has a central office with a lobby, reception, and two secure areas: the server room (requires keycard and PIN) and the executive floor (requires keycard only). Recently, employees have reported seeing unfamiliar people in restricted areas. Security logs show keycard access for the server room only during business hours, but no anomalies. However, the executive floor logs show multiple entries by a single employee, John from Sales, at odd hours. John claims he was working late. The company has a policy that all employees must wear ID badges visibly. You observe that employees often hold doors open for colleagues, and the receptionist does not verify visitor badges. Which of the following actions should you recommend FIRST to address the most likely attack vector?
7A penetration tester calls an employee claiming to be from the IT help desk and asks for their password to perform a 'security update'. The employee provides the password. Which social engineering technique is being used?
8Which TWO of the following are effective physical security controls to prevent tailgating?
9Refer to the exhibit. An attacker gains access to the user's workstation and wants to find a file containing passwords. Which file is most likely to contain credentials?
10A security auditor is assessing the physical security of a corporate office building that houses a data center. The building has a single main entrance with a reception desk staffed during business hours (8 AM to 6 PM). After hours, employees use a keycard reader to access the building. The data center itself requires a separate keycard and a 6-digit PIN. The auditor notices that during lunch hours (12-1 PM), the reception desk is often unattended, and employees frequently hold the door for others to avoid using their keycard. Additionally, a recent social engineering test revealed that an attacker was able to call the help desk, claim to be a new employee, and request a password reset, which was granted without proper verification. Based on this scenario, which of the following is the MOST effective combination of controls to mitigate both the physical and social engineering weaknesses?
11Refer to the exhibit. A security analyst reviews the firewall log and notices that user jdoe accessed a file server via SMB (port 445) from an internal IP (10.0.0.45) that is not the usual file server subnet. Which type of social engineering attack is most likely being attempted?
12Drag and drop the steps to perform a successful social engineering attack in a penetration test into the correct order.
13Match each wireless attack to its description.
14A security analyst is reviewing logs from a recent social engineering engagement. The attacker used a phishing email that appeared to come from the company's CEO, requesting that the recipient update their payroll direct deposit information via a link. The link led to a credential harvesting page. Which type of social engineering attack is this?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Identify social engineering vectors and physical bypass techniques, then select the control that actually stops them: mantrap or turnstile for tailgating, callback verification for help desk impersonation, and log correlation for SMB anomalies. The key is matching the countermeasure to the specific attack.
The Courseiva CEH question bank contains 14 questions in the Social Engineering and Physical Security domain, covering the 7% of the exam attributed to this domain in the official EC-Council blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Social Engineering and Physical Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included