CEH Social Engineering and Physical Security Practice Question
Exhibit
Refer to the exhibit. ``` Firewall Log: Date: 2023-10-12 Time: 14:23:45 Source IP: 10.0.0.45 Destination IP: 192.168.1.100 Protocol: TCP Port: 445 Action: ALLOW User: jdoe Reason: Rule ID 3 (SMB access to file server) ``` Exhibit:
Refer to the exhibit. A security analyst reviews the firewall log and notices that user jdoe accessed a file server via SMB (port 445) from an internal IP (10.0.0.45) that is not the usual file server subnet. Which type of social engineering attack is most likely being attempted?
⚠ Common exam trap
The trap here is that candidates see SMB and internal IP and immediately think of a technical attack like phishing or baiting, but the key clue is the physical access implied by the unusual subnet, which points to tailgating as the social engineering vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tailgating
The firewall log shows user jdoe accessing a file server via SMB (port 445) from an internal IP (10.0.0.45) that is not on the usual file server subnet. This indicates the attacker has physically entered the building or restricted area by following an authorized person (tailgating) and then connected a rogue device to the internal network to perform lateral movement. Tailgating is the social engineering attack that relies on gaining physical access by exploiting trust or courtesy, which aligns with the unauthorized internal IP and SMB activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a social engineering technique involving deceptive electronic communications, such as emails or instant messages, designed to trick recipients into revealing sensitive information or performing malicious actions. While it can lead to system compromise, the direct manifestation in firewall logs would typically be outbound connections from an infected host or credential theft, not an unauthorized internal IP directly attempting SMB connections without a prior successful compromise leading to internal network access.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a social engineering attack conducted over the telephone where attackers impersonate legitimate entities to manipulate victims into divulging confidential information or performing specific actions. This method primarily exploits human trust through verbal communication and does not directly result in an unauthorized internal IP address appearing in firewall logs attempting SMB connections, as it is not a direct network-level attack.
- ✓
Tailgating
Why this is correct
Tailgating is a physical security breach where an unauthorized individual gains access to a restricted area by following an authorized person through a controlled entry point without proper authentication. Once physically inside the secured perimeter, the attacker can connect their device to the internal network, potentially assigning themselves an unauthorized internal IP address, which would then be logged by the firewall attempting connections like SMB, indicating an internal compromise.
- ✗
Baiting
Why it's wrong here
Baiting is a social engineering attack that involves leaving a malware-infected physical device, such as a USB drive, in a public place, hoping a curious victim will pick it up and connect it to their computer. While a successful baiting attack can lead to network compromise and subsequent unauthorized network activity, the initial unauthorized internal IP connection to SMB in firewall logs is not the direct, primary indicator of a baiting attack itself, which focuses on the initial infection vector via physical media.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.