17+ practice questions focused on Social Engineering and Physical Security — one of the most tested topics on the Certified Ethical Hacker CEH exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Social Engineering and Physical Security PracticeWhich TWO of the following are effective methods to prevent dumpster diving attacks? (Choose two.)
Explanation: Shredding sensitive documents before disposal (Option B) is effective because it physically destroys the information, making it impossible to reconstruct from discarded paper. This directly counters dumpster diving, where attackers retrieve documents to extract confidential data like passwords or network diagrams. Using locked bins for discarded materials (Option C) is also effective as it prevents unauthorized individuals from accessing the contents of the bins, thereby securing the discarded information until it can be properly destroyed or disposed of.
Which THREE of the following are common indicators of a social engineering attack? (Choose three.)
Explanation: Social engineers frequently fabricate a sense of urgency to bypass the victim's rational decision-making. By claiming an immediate deadline or threat (e.g., 'Your account will be locked in 24 hours'), the attacker pressures the target into acting without verifying the request, a tactic rooted in the psychological principle of scarcity. Additionally, social engineering attempts, particularly phishing emails, often originate from non-native English speakers or are created hastily, leading to noticeable spelling and grammatical mistakes (Option D). These errors can also be intentionally introduced to bypass spam filters or to target less discerning individuals. Furthermore, attackers frequently impersonate individuals in positions of power or trust, such as CEOs, IT administrators, government officials, or law enforcement (Option E). This tactic, known as 'pretexting' or 'impersonation,' leverages the victim's natural inclination to comply with authority figures, pressuring them to act without critical evaluation.
An organization is implementing a social engineering defense program. Which TWO measures are most effective in reducing the risk of phishing attacks? (Choose two.)
Explanation: Regular security awareness training (C) directly addresses the human factor in phishing attacks. Employees learn to identify suspicious emails, avoid clicking malicious links, and report incidents promptly, which is critical since technical controls alone cannot prevent all phishing attempts. This training reinforces behaviors like verifying sender addresses and not bypassing security protocols, reducing the likelihood of successful social engineering. Concurrently, installing advanced email filtering and anti-malware solutions (E) provides a crucial technical layer of defense by detecting and blocking malicious emails before they even reach an employee's inbox, significantly reducing the volume of phishing attempts users are exposed to and catching sophisticated threats that might bypass human detection.
A penetration tester is assessing an organization's physical security. The tester wants to gain unauthorized access to a secured server room that uses a biometric fingerprint scanner. Which of the following techniques would be MOST effective for bypassing the biometric scanner?
Explanation: Gelatin molds can replicate the exact ridge and valley patterns of a fingerprint, which many capacitive and optical fingerprint scanners read. This bypasses the biometric authentication without requiring the user's cooperation, making it the most direct method to defeat the scanner itself.
During a social engineering engagement, a tester calls the help desk posing as an employee from the IT department. The tester claims to be working on a critical system update and needs the employee's password to proceed. Which type of social engineering attack is being executed?
Explanation: Pretexting involves creating a fabricated scenario (pretext) to manipulate a target into divulging information. In this case, the tester falsely claims to be from the IT department working on a critical system update, which is a classic pretext to gain trust and obtain the employee's password. This differs from other social engineering types because it relies on a constructed identity and false narrative rather than a technical lure or direct exchange.
+12 more Social Engineering and Physical Security questions available
Practice all Social Engineering and Physical Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Social Engineering and Physical Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Social Engineering and Physical Security questions on the CEH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Social Engineering and Physical Security is tested as part of the Certified Ethical Hacker CEH blueprint. Practicing with targeted Social Engineering and Physical Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CEH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Social Engineering and Physical Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Social Engineering and Physical Security practice session with instant scoring and detailed explanations.
Start Social Engineering and Physical Security Practice →