CEH Practice Question: Malware, Social Engineering and Network Attacks
A user receives a phone call from someone claiming to be from IT support, asking for their password to perform a system update. This is an example of which social engineering technique?
⚠ Common exam trap
Watch out — candidates often confuse vishing (voice phishing) with pretexting, but the key differentiator is that pretexting involves a fabricated identity and scenario (pretext) to establish trust, whereas vishing is simply phishing conducted over voice without necessarily building a detailed false narrative.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is a social engineering technique where an attacker fabricates a scenario (pretext) to manipulate a target into divulging sensitive information. In this case, the caller creates a false identity (IT support) and a false reason (system update) to trick the user into revealing their password. This differs from other techniques because it relies on a constructed narrative rather than malicious software or direct impersonation via email or phone alone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Baiting
Why it's wrong here
Baiting relies on an attacker leaving a physical or digital 'bait' for the victim to discover and interact with, such as a malware-laden USB drive or a tempting 'free download' link. The victim is lured by the promise of something desirable, triggering their curiosity or greed. This scenario, involving a direct phone call without an initial enticing 'offer' to be found, does not align with the typical characteristics of a baiting attack.
- ✓
Pretexting
Why this is correct
Pretexting involves an attacker fabricating a believable scenario and a false identity to manipulate a victim into divulging sensitive information. The attacker creates a detailed backstory, often impersonating someone in authority or a trusted entity, to establish a sense of legitimacy and urgency. This elaborate setup is designed to overcome the victim's skepticism and directly solicit specific data, like a password, through social engineering.
- ✗
Phishing
Why it's wrong here
Phishing is a broad social engineering technique primarily executed through electronic communication, typically email or fraudulent websites, designed to trick recipients into revealing personal information or clicking malicious links. It often involves impersonating a legitimate organization to create a sense of trust or urgency. While 'vishing' is a form of phishing, the term 'phishing' alone generally refers to text-based or web-based attacks, not direct voice calls.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a social engineering attack conducted over the telephone, where attackers attempt to solicit sensitive information by impersonating trusted entities. Unlike pretexting, vishing often relies on generic, high-volume scripts that exploit fear or urgency, such as fake IRS calls or tech support scams, without necessarily developing a highly specific, tailored backstory for the individual target. The key distinction here is the lack of a deeply fabricated, individualized scenario that defines pretexting.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.