Courseiva

CCNA Social Engineering and Physical Security Questions

14 questions · Social Engineering and Physical Security · All types, answers revealed

1
MCQeasy

Refer to the exhibit. An attacker gains access to the user's workstation and wants to find a file containing passwords. Which file is most likely to contain credentials?

A.User profile (C:\Users\jdoe)
B.Home directory on \\fileserver\home\jdoe
C.logon.bat script
D.Active Directory database (NTDS.dit)
AnswerC

A logon.bat script is a specific executable file often configured to run automatically when a user logs onto a domain-joined machine. These scripts are frequently used to map network drives, configure printers, or execute other setup tasks, and unfortunately, they sometimes contain hardcoded usernames and passwords for network resources. An attacker gaining access to this script can directly read these embedded credentials, making it a prime target for credential harvesting and subsequent lateral movement within the network.

Why this answer

Logon.bat scripts are commonly used in Windows environments to map network drives or perform startup tasks, and administrators often embed plaintext credentials in such scripts for automation. An attacker who compromises the workstation can read this batch file to extract stored passwords, making it a high-value target for credential theft.

Exam trap

EC-Council often tests the misconception that credentials are always stored in system databases like NTDS.dit or SAM, but the trap here is that attackers target easily accessible, plaintext files like logon scripts that users or administrators create for convenience.

How to eliminate wrong answers

Option A is wrong because the user profile (C:\Users\jdoe) contains personal files and settings but not typically stored credentials in plaintext; passwords are usually hashed and stored in the SAM hive, not in profile folders. Option B is wrong because the home directory on \\fileserver\home\jdoe is a network share that may contain user data but is not a default location for credential files; accessing it requires network authentication, and it is less likely to contain plaintext passwords than a local script. Option D is wrong because the Active Directory database (NTDS.dit) contains domain credential hashes, but it resides on a domain controller, not on the user's workstation, and an attacker with only local workstation access cannot directly read it without privilege escalation or network traversal.

2
Multi-Selecthard

Which TWO of the following are effective physical security controls to prevent tailgating?

Select 2 answers
A.Biometric door lock
B.Mantrap
C.CCTV cameras
D.Security guard
E.Turnstile with one-way access
AnswersB, E

A mantrap is a highly effective physical security control consisting of a small vestibule with two interlocking doors. It is designed to ensure that only one person can pass through at a time; the first door must close and lock before the second door can open. This sequential operation physically prevents tailgating by isolating individuals and enforcing single-person occupancy per access cycle.

Why this answer

A mantrap is a physical security control consisting of two interlocking doors that create a small vestibule. Only one door can be opened at a time, and the system verifies that only one person enters before allowing the second door to open. This design directly prevents tailgating by trapping unauthorized individuals who attempt to follow an authorized person through the first door.

Exam trap

The trap here is that candidates often confuse 'preventive' controls (like mantrap and turnstile) with 'detective' controls (like CCTV) or 'deterrent' controls (like security guards), leading them to select CCTV or guards as effective tailgating prevention measures.

3
MCQmedium

A penetration tester calls an employee claiming to be from the IT help desk and asks for their password to perform a 'security update'. The employee provides the password. Which social engineering technique is being used?

A.Pretexting
B.Tailgating
C.Quid pro quo
D.Phishing
AnswerA

Pretexting uses a fabricated scenario to obtain information.

Why this answer

The attacker is fabricating a scenario (IT help desk performing a security update) to manipulate the target into revealing sensitive information. This is the essence of pretexting, where the attacker creates a false identity or situation to gain trust and extract data. Unlike phishing, which typically uses malicious links or attachments, this attack relies purely on verbal impersonation and social manipulation.

Exam trap

The trap here is that candidates confuse pretexting with phishing because both involve deception, but phishing specifically uses electronic channels (email, fake login pages) while pretexting can occur over voice or in person without any technical payload.

How to eliminate wrong answers

Option B is wrong because tailgating involves physically following an authorized person into a restricted area without their consent, not deceiving someone over the phone. Option C is wrong because quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password'), whereas here the attacker simply demands the password under a false pretense. Option D is wrong because phishing typically uses electronic communication (email, SMS, fake websites) to trick victims into clicking a link or downloading malware, not a direct phone call asking for credentials.

4
Matchingmedium

Match each wireless attack to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Exploiting weak encryption in older Wi-Fi

Rogue access point mimicking a legitimate one

Forcing clients to disconnect from AP

Intercepting the 4-way handshake for cracking

Unauthorized access to Bluetooth devices

Why these pairings

Correct matches: Evil Twin (A), Rogue AP (C), War Driving (F) are correctly paired. WEP Cracking (D is swapped with War Driving; B and E are misidentified).

5
MCQeasy

Which of the following is the BEST defense against tailgating attacks in a secure facility?

A.Hiring security guards
B.Reviewing keycard access logs
C.Installing CCTV cameras
D.Implementing a mantrap at the entrance
AnswerD

Implementing a mantrap at the entrance is the most effective defense because it is a physical security mechanism designed specifically to prevent tailgating. A mantrap consists of two interlocking doors, where the first door must close and lock before the second door can open, typically allowing only one person to pass through at a time after successful authentication. This physically enforces single-person entry, making it virtually impossible for a second individual to follow an authorized person into a restricted area.

Why this answer

A mantrap is a physical security access control system consisting of two interlocking doors that create a small vestibule. Only one door can be opened at a time, and authentication (e.g., keycard + biometric) is required to pass through both. This design physically prevents an unauthorized person from following an authorized person into the facility, directly mitigating tailgating attacks by enforcing strict one-person-per-authentication entry.

Exam trap

EC-Council often tests the distinction between preventive, detective, and corrective controls; the trap here is that candidates mistake surveillance (CCTV) or logging (access logs) for active prevention, when only a mantrap provides a physical barrier that stops tailgating in real time.

How to eliminate wrong answers

Option A is wrong because hiring security guards relies on human vigilance, which is fallible and can be bypassed through distraction or social engineering, and does not provide a mechanical barrier against tailgating. Option B is wrong because reviewing keycard access logs is a detective control that identifies tailgating incidents after they occur, not a preventive defense that stops the attack in real time. Option C is wrong because installing CCTV cameras provides surveillance and evidence but does not physically prevent an unauthorized person from entering behind an authorized person; it is a passive monitoring control, not an active access control.

6
Drag & Dropmedium

Drag and drop the steps to perform a successful social engineering attack in a penetration test into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

In a social engineering penetration test, the correct sequence is Research (gather intelligence on the target), Craft Pretext (create a believable scenario), Choose Channel (select communication medium), Execute (deliver the attack), and Document (record findings). This order ensures the attack is tailored and effective, as each step builds on the previous one.

7
MCQmedium

An employee receives an email that appears to be from the CEO, asking the employee to urgently wire funds to a vendor. The email address is slightly misspelled. What type of social engineering attack is this?

A.Pharming
B.Spear phishing
C.Whaling
D.Vishing
AnswerC

Whaling is a specialized form of spear phishing that specifically targets high-profile individuals, such as senior executives, CEOs, or government officials, or impersonates them to deceive employees. In this scenario, an email appearing to be from the CEO directly aligns with the definition of whaling, as it leverages the authority of a top executive to induce a specific action. The objective is often to trick recipients into making large financial transfers or divulging sensitive corporate data, exploiting the perceived urgency and command from a C-level executive.

Why this answer

This is a whaling attack because it specifically targets a high-profile individual (the CEO) to deceive another employee into performing a financial action. The slight misspelling of the email address is a classic whaling technique, as the attacker impersonates a senior executive to exploit authority and urgency. Unlike generic phishing, whaling focuses on C-level executives or decision-makers.

Exam trap

EC-Council often tests the distinction between spear phishing and whaling by emphasizing that whaling specifically targets senior executives, while spear phishing can target any individual or role within an organization.

How to eliminate wrong answers

Option A is wrong because pharming redirects users from legitimate websites to fraudulent ones by manipulating DNS or host files, not by sending deceptive emails. Option B is wrong because spear phishing targets a specific individual or organization but does not necessarily involve impersonating a senior executive; the key differentiator here is the impersonation of the CEO, which is the hallmark of whaling. Option D is wrong because vishing (voice phishing) uses phone calls or voice messages, not email, to trick victims.

8
MCQhard

You are a security consultant hired by a mid-sized company with 500 employees. The company has a central office with a lobby, reception, and two secure areas: the server room (requires keycard and PIN) and the executive floor (requires keycard only). Recently, employees have reported seeing unfamiliar people in restricted areas. Security logs show keycard access for the server room only during business hours, but no anomalies. However, the executive floor logs show multiple entries by a single employee, John from Sales, at odd hours. John claims he was working late. The company has a policy that all employees must wear ID badges visibly. You observe that employees often hold doors open for colleagues, and the receptionist does not verify visitor badges. Which of the following actions should you recommend FIRST to address the most likely attack vector?

A.Investigate John's activities and consider disciplinary action
B.Upgrade keycard readers to biometric scanners
C.Implement mantraps and enforce a policy of one person per keycard entry
D.Install additional CCTV cameras in hallways
AnswerC

Mantraps are highly effective physical security controls consisting of two interlocking doors, designed to permit only one person to pass through at a time after successful authentication. This physical barrier directly prevents tailgating by making it impossible for a second individual to enter behind an authorized person. Coupling this technical control with a strictly enforced policy reinforces security protocols, ensuring both physical and administrative measures actively mitigate the tailgating threat.

Why this answer

The most likely attack vector is tailgating (piggybacking), where unauthorized individuals gain physical access by following an authorized employee through a secured door without using their own credentials. Option C directly addresses this by implementing mantraps (a small room with two interlocking doors that only allows one person to pass at a time) and enforcing a strict one-person-per-keycard-entry policy, which physically prevents tailgating. This is the first and most effective control because it mitigates the root cause—social engineering exploiting human courtesy—rather than focusing on symptoms like John's after-hours access or adding surveillance that doesn't prevent the act.

Exam trap

EC-Council often tests the distinction between authentication (e.g., biometrics) and access control (e.g., mantraps), and the trap here is that candidates confuse improving credential verification with preventing the social engineering technique of tailgating, leading them to choose a more expensive but ineffective solution like biometric readers.

How to eliminate wrong answers

Option A is wrong because investigating John's activities focuses on a single employee's behavior (which may be legitimate) rather than addressing the systemic vulnerability of tailgating that allows unfamiliar people into restricted areas. Option B is wrong because upgrading to biometric scanners improves authentication but does not prevent tailgating; an unauthorized person can still follow an authenticated employee through the door after the biometric scan. Option D is wrong because installing additional CCTV cameras only provides passive monitoring and evidence collection after an incident, not active prevention of the tailgating attack vector.

9
MCQmedium

A penetration tester is assessing an organization's physical security. The tester wants to gain unauthorized access to a secured server room that uses a biometric fingerprint scanner. Which of the following techniques would be MOST effective for bypassing the biometric scanner?

A.Shoulder surfing the authorized user's fingerprint pattern
B.Picking the lock on the server room door
C.Using a gelatin mold of an authorized user's fingerprint
D.Tailgating behind an authorized employee
AnswerC

Using a gelatin mold is a classic and often effective method for creating a spoofed fingerprint, as gelatin can accurately capture and replicate the unique ridge patterns and valleys of an authorized user's print. When pressed against a scanner, particularly older optical or capacitive types lacking advanced liveness detection, the gelatin replica can mimic the electrical or optical properties of a real finger. This allows the penetration tester to deceive the biometric system into granting access.

Why this answer

Gelatin molds can replicate the exact ridge and valley patterns of a fingerprint, which many capacitive and optical fingerprint scanners read. This bypasses the biometric authentication without requiring the user's cooperation, making it the most direct method to defeat the scanner itself.

Exam trap

The trap here is that candidates often choose tailgating (Option D) as the easiest social engineering method, but the question specifically asks for bypassing the biometric scanner, not the door lock or human controls.

How to eliminate wrong answers

Option A is wrong because shoulder surfing captures only a visual pattern, not the three-dimensional ridge details or capacitance differences needed to spoof a fingerprint scanner. Option B is wrong because picking the lock bypasses the door lock but does not address the biometric scanner, which would still need to be defeated to gain access. Option D is wrong because tailgating relies on following an authorized person through the door, but it does not bypass the biometric scanner itself and may be prevented by mantraps or security awareness.

10
MCQhard

A security auditor is assessing the physical security of a corporate office building that houses a data center. The building has a single main entrance with a reception desk staffed during business hours (8 AM to 6 PM). After hours, employees use a keycard reader to access the building. The data center itself requires a separate keycard and a 6-digit PIN. The auditor notices that during lunch hours (12-1 PM), the reception desk is often unattended, and employees frequently hold the door for others to avoid using their keycard. Additionally, a recent social engineering test revealed that an attacker was able to call the help desk, claim to be a new employee, and request a password reset, which was granted without proper verification. Based on this scenario, which of the following is the MOST effective combination of controls to mitigate both the physical and social engineering weaknesses?

A.Install a mantrap at the main entrance and require two-factor authentication for the data center door.
B.Install a mantrap at the main entrance and require multi-factor authentication (MFA) for all password reset requests.
C.Deploy security guards at the entrance 24/7 and implement a policy that all visitors must be escorted.
D.Implement a callback verification process for all password reset requests and require a manager approval.
AnswerB

A mantrap at the main entrance is a robust physical security control that effectively prevents tailgating and unauthorized physical access to the premises. Simultaneously, requiring multi-factor authentication (MFA) for all password reset requests significantly strengthens logical security by making it much harder for social engineers to gain unauthorized account access, even if they successfully trick an employee into initiating a reset. This combination addresses both physical and social engineering vulnerabilities comprehensively.

Why this answer

It addresses both weaknesses: a mantrap prevents tailgating at the main entrance (physical security), and requiring MFA for password reset requests mitigates the social engineering attack by adding an authentication factor beyond just a phone call. This combination directly counters the observed vulnerabilities—unattended reception and weak identity verification—without over-engineering or leaving gaps.

Exam trap

The trap here is that candidates focus on the most obvious single weakness (e.g., tailgating or password reset) and choose a control that only fixes that one, missing the requirement for a combination that addresses both physical and social engineering flaws simultaneously.

How to eliminate wrong answers

Option A is wrong because while a mantrap stops tailgating, requiring two-factor authentication only for the data center door does nothing to prevent the social engineering attack on the help desk (password reset). Option C is wrong because deploying 24/7 guards and an escort policy is costly and does not address the social engineering weakness; the attacker called the help desk, not the physical entrance. Option D is wrong because a callback verification process and manager approval only address the social engineering vector, leaving the physical tailgating problem during lunch hours completely unmitigated.

11
MCQhard

Refer to the exhibit. A security analyst reviews the firewall log and notices that user jdoe accessed a file server via SMB (port 445) from an internal IP (10.0.0.45) that is not the usual file server subnet. Which type of social engineering attack is most likely being attempted?

A.Phishing
B.Vishing
C.Tailgating
D.Baiting
AnswerC

Tailgating is a physical security breach where an unauthorized individual gains access to a restricted area by following an authorized person through a controlled entry point without proper authentication. Once physically inside the secured perimeter, the attacker can connect their device to the internal network, potentially assigning themselves an unauthorized internal IP address, which would then be logged by the firewall attempting connections like SMB, indicating an internal compromise.

Why this answer

The firewall log shows user jdoe accessing a file server via SMB (port 445) from an internal IP (10.0.0.45) that is not on the usual file server subnet. This indicates the attacker has physically entered the building or restricted area by following an authorized person (tailgating) and then connected a rogue device to the internal network to perform lateral movement. Tailgating is the social engineering attack that relies on gaining physical access by exploiting trust or courtesy, which aligns with the unauthorized internal IP and SMB activity.

Exam trap

The trap here is that candidates see SMB and internal IP and immediately think of a technical attack like phishing or baiting, but the key clue is the physical access implied by the unusual subnet, which points to tailgating as the social engineering vector.

How to eliminate wrong answers

Option A is wrong because phishing involves sending deceptive emails or messages to trick users into revealing credentials or installing malware, not physically accessing a network and using SMB from an unusual internal IP. Option B is wrong because vishing (voice phishing) uses phone calls to extract sensitive information, not physical intrusion or network-level SMB connections. Option D is wrong because baiting involves offering something enticing (e.g., infected USB drives) to lure victims, not directly following someone into a restricted area to gain network access.

12
MCQhard

During a social engineering engagement, a tester calls the help desk posing as an employee from the IT department. The tester claims to be working on a critical system update and needs the employee's password to proceed. Which type of social engineering attack is being executed?

A.Quid pro quo
B.Baiting
C.Pretexting
D.Phishing
AnswerC

Pretexting is a highly targeted social engineering technique where an attacker creates a fabricated scenario or 'pretext' to manipulate a victim into divulging sensitive information or performing an action. This often involves extensive research to develop a believable false identity and backstory, making the attacker appear legitimate and authoritative during direct interactions like phone calls. The tester's action of calling with a false identity to extract information perfectly aligns with this method's characteristics.

Why this answer

Pretexting involves creating a fabricated scenario (pretext) to manipulate a target into divulging information. In this case, the tester falsely claims to be from the IT department working on a critical system update, which is a classic pretext to gain trust and obtain the employee's password. This differs from other social engineering types because it relies on a constructed identity and false narrative rather than a technical lure or direct exchange.

Exam trap

The trap here is that candidates confuse pretexting with phishing because both involve deception, but phishing specifically refers to electronic communication (email, SMS) while pretexting can occur over the phone or in person, and the CEH exam tests this distinction by presenting a phone call scenario without any digital lure.

How to eliminate wrong answers

Option A is wrong because quid pro quo involves offering a service or benefit in exchange for information (e.g., 'I'll fix your computer if you give me your password'), not simply claiming a false identity. Option B is wrong because baiting uses a physical or digital lure (e.g., infected USB drive or free download) to entice the victim, not a fabricated story. Option D is wrong because phishing is a mass-deceptive technique using electronic communication (e.g., email, SMS) to trick victims into clicking malicious links or providing credentials, not a direct phone call with a crafted pretext.

13
MCQhard

Refer to the exhibit. A security analyst runs ping and arp commands. What is the most likely attack occurring?

A.Distributed denial of service (DDoS) attack
B.MAC flooding attack
C.ARP spoofing attack
D.Ping flood attack
AnswerC

An ARP spoofing attack, also known as ARP poisoning, involves an attacker sending forged Address Resolution Protocol (ARP) replies to a target system, associating the attacker's MAC address with the IP address of another legitimate device on the local network. The exhibit's indication of duplicate MAC addresses for different IP addresses in the ARP cache is a definitive symptom of this attack. This allows the attacker to intercept, modify, or drop traffic intended for the legitimate device, effectively performing a man-in-the-middle attack.

Why this answer

The combination of `ping` and `arp` commands reveals an ARP spoofing attack. The `arp -a` output shows the same MAC address (00-11-22-33-44-55) mapped to multiple IP addresses (192.168.1.1 and 192.168.1.2), which is a classic indicator of ARP cache poisoning. The `ping` commands confirm that both IPs are reachable, but the duplicate MAC entry proves an attacker is intercepting traffic by associating their MAC with multiple IPs.

Exam trap

The trap here is that candidates confuse MAC flooding (which targets switch CAM tables) with ARP spoofing (which targets host ARP caches), but the exhibit's `arp -a` output showing multiple IPs for one MAC is the definitive sign of ARP cache poisoning, not a switch-level attack.

How to eliminate wrong answers

Option A is wrong because a DDoS attack would overwhelm the target with traffic from multiple sources, not cause duplicate MAC entries in the ARP cache. Option B is wrong because a MAC flooding attack fills the switch's CAM table with fake MAC addresses to force it into hub mode, but the exhibit shows ARP table entries, not switch behavior or CAM table overflow. Option D is wrong because a ping flood attack sends a high volume of ICMP echo requests to consume bandwidth, but the exhibit shows only a few ping replies and no indication of resource exhaustion or abnormal traffic volume.

14
MCQeasy

You are a security consultant for a mid-sized company with 500 employees. The company has a secure data center with a biometric access control system. Recently, a contractor was able to enter the data center without authorization by claiming he forgot his badge and an employee held the door for him. The contractor then accessed sensitive servers and exfiltrated data. The company wants to prevent such incidents. Which physical security control would be most effective in preventing this type of attack?

A.Install CCTV cameras to monitor the entrance.
B.Require employees to wear RFID badges at all times.
C.Implement a mantrap with biometric and badge authentication.
D.Hire additional security guards at the entrance.
AnswerC

Mantraps physically prevent tailgating by requiring one person at a time.

Why this answer

A mantrap with biometric and badge authentication enforces strict two-person authentication: both the contractor and the employee must independently authenticate before the mantrap doors unlock. This prevents tailgating (piggybacking) by ensuring only one person enters per authentication cycle, eliminating the social engineering vector where an employee holds the door for an unauthorized individual.

Exam trap

The trap here is that candidates often choose CCTV or guards because they seem like obvious physical security measures, but the question specifically targets tailgating/piggybacking, which only a mantrap with dual authentication can reliably prevent.

How to eliminate wrong answers

Option A is wrong because CCTV cameras are passive monitoring tools; they do not prevent unauthorized entry, only record it after the fact, and cannot stop tailgating in real time. Option B is wrong because requiring RFID badges at all times does not prevent an employee from holding the door for an unauthorized person; badges alone cannot enforce one-person-per-entry. Option D is wrong because additional security guards can still be socially engineered or fail to notice tailgating, and guards introduce human error and cost without the deterministic access control of a mantrap.

Ready to test yourself?

Try a timed practice session using only Social Engineering and Physical Security questions.