CEH Practice Question: Malware, Social Engineering and Network Attacks
A penetration tester uses the Social Engineering Toolkit (SET) to create a malicious USB drive that autoruns when inserted. Which social engineering technique is being employed?
⚠ Common exam trap
Watch out — candidates often confuse baiting with phishing because both involve tricking the user, but baiting specifically relies on a physical lure (like a USB drive) rather than a digital message or link.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Baiting
Baiting is the correct answer because the penetration tester is using a physical device (USB drive) to exploit human curiosity or greed, enticing the target to insert it into a system. The Social Engineering Toolkit (SET) can create an autorun.inf file that triggers a payload upon insertion, which is a classic baiting attack that relies on the victim's action to compromise the system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tailgating
Why it's wrong here
Tailgating is a physical security bypass technique where an unauthorized individual follows an authorized person through a controlled access point, such as a door requiring a badge, without presenting their own credentials. This method relies on human courtesy or inattention rather than digital manipulation or malicious software. It is distinct from the types of attacks typically automated or facilitated by the Social Engineering Toolkit (SET), which focuses more on digital payloads and communication-based deception.
- ✓
Baiting
Why this is correct
Baiting is a social engineering attack that leverages human curiosity or greed by leaving physical media, such as USB drives or CDs, infected with malware in public or semi-public locations. The attacker relies on the victim finding the device and inserting it into their computer, thereby executing the malicious payload. The Social Engineering Toolkit (SET) is specifically designed to create such malicious payloads and facilitate the setup for baiting attacks, making it a direct match for this technique.
- ✗
Pretexting
Why it's wrong here
Pretexting involves creating an elaborate, fabricated scenario or 'pretext' to trick a target into divulging sensitive information or performing an action they wouldn't normally do. This technique heavily relies on a convincing story and often involves sustained verbal communication, typically over the phone, where the attacker impersonates someone in authority or a trusted entity. Unlike attacks involving physical media or direct web-based exploits, pretexting primarily manipulates human trust and decision-making through dialogue, which is not the primary function of SET's automated attack vectors.
- ✗
Phishing
Why it's wrong here
Phishing is a broad category of social engineering attacks that utilize deceptive electronic communications, most commonly email, to trick recipients into revealing sensitive information, clicking malicious links, or downloading malware. While the Social Engineering Toolkit (SET) can generate phishing web pages and send mass emails, 'phishing' describes the general method of electronic deception. The question's context, implying a specific SET module for a particular attack type, points more directly to baiting when considering the use of physical media as an enticement, rather than the general electronic delivery of phishing.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.