EC-Council Certified Ethical Hacker (CEH) v12Social EngineeringEasy

A disgruntled former employee, seeking revenge against their previous company, creates a fake social media profile impersonating a senior executive. They then use this profile to send malicious links and gather sensitive information from current employees, leveraging the trust associated with the executive's position. Which social engineering technique is primarily being employed here?

  1. AWatering Hole Attack
  2. BImpersonation
  3. CPretexting
  4. DBaiting
Show answer & explanation

Correct answer: B. Impersonation

The scenario clearly describes an attacker pretending to be someone else (a senior executive) to gain trust and extract information, which is the definition of impersonation. While elements of social engineering are present, the direct act of posing as another individual is the core technique.

Why the other options are wrong

  • A. A watering hole attack involves compromising a website frequently visited by a target group to infect them when they visit.
  • C. Pretexting involves creating a fabricated scenario (a 'pretext') to engage a victim and manipulate them into divulging information.
  • D. Baiting involves offering something enticing (like a free download) to trick victims into taking an action that compromises their security.

Impersonation

A social engineering technique where an attacker pretends to be a different person or entity to gain trust and access to information or systems.

  • Involves assuming a false identity.
  • Relies on the victim's trust in the assumed identity.
  • Can be done online or offline.

Memory trick: Impersonation is playing a role to steal your data.

More Social Engineering questions