Pretexting Social Engineering: Phone Call from Fake IT Support
A user receives a phone call from someone claiming to be from IT support, asking for their password to troubleshoot an issue. Which social engineering technique is being used?
Quick Answer
The answer is pretexting. This social engineering technique involves the attacker fabricating a believable scenario—in this case, posing as IT support—to manipulate the target into divulging sensitive information like a password. Unlike phishing, which often relies on urgency or fear via email, pretexting builds a false identity and context over a phone call to lower the victim’s defenses. On the Certified Ethical Hacker CEH exam, this scenario tests your ability to distinguish pretexting from other social engineering methods such as baiting or tailgating; a common trap is confusing it with phishing because both seek credentials, but the key differentiator is the live, role-based deception over voice. To remember, think of the word “pretext” as a “pre-written script” the attacker follows to act out a role, so if a caller invents a fake reason to ask for your password, it’s always pretexting.
⚠ Common exam trap
Watch out — candidates often confuse vishing with pretexting because both involve phone calls, but vishing is a subset of phishing that relies on automated or scripted voice messages, whereas pretexting involves a live, interactive social engineering scenario where the attacker fabricates a detailed identity and story.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is a social engineering technique where the attacker creates a fabricated scenario (pretext) to trick the victim into divulging sensitive information. In this case, the caller impersonates IT support to establish a false sense of authority and urgency, directly asking for the password. This differs from vishing, which is voice-based phishing but typically involves a generic, automated or scripted request rather than a crafted, interactive pretext.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is typically conducted via email, not phone calls.
- ✓
Pretexting
Why this is correct
Correct. The attacker uses a false pretext (IT support) to obtain sensitive information.
- ✗
Baiting
Why it's wrong here
Baiting involves offering something enticing (e.g., a USB drive) to lure the victim.
- ✗
Vishing
Why it's wrong here
Vishing is voice phishing, but the key element here is the false identity, which is pretexting.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user receives a phone call from someone claiming to be from IT support, asking for their password to perform a system update. This is an example of which social engineering technique?
medium- A.Baiting
- ✓ B.Pretexting
- C.Phishing
- D.Vishing
Why B: Pretexting is a social engineering technique where an attacker fabricates a scenario (pretext) to manipulate a target into divulging sensitive information. In this case, the caller creates a false identity (IT support) and a false reason (system update) to trick the user into revealing their password. This differs from other techniques because it relies on a constructed narrative rather than malicious software or direct impersonation via email or phone alone.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.