CEH Practice Question: Malware, Social Engineering and Network Attacks
A user receives a text message claiming their bank account is locked and requiring them to click a link to verify. This social engineering method is called:
⚠ Common exam trap
The CEH exam often tests the distinction between phishing (email), vishing (voice), and SMiShing (SMS) by presenting a scenario that clearly involves a text message, leading candidates to mistakenly choose 'Phishing' due to its broader familiarity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SMiShing
SMiShing (SMS phishing) is the correct term because the attack vector is a text message (SMS) that tricks the user into clicking a malicious link. Unlike email-based phishing, SMiShing exploits the higher trust users often place in SMS messages and the limited security controls on mobile devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a broad social engineering technique where attackers attempt to acquire sensitive information, such as usernames, passwords, and credit card details, by masquerading as a trustworthy entity in an electronic communication. While SMiShing is a subset, the term "phishing" typically refers to attacks conducted primarily through email, making it a less specific and accurate description for an attack delivered via text message.
- ✗
Whaling
Why it's wrong here
Whaling is a highly specialized form of phishing that specifically targets high-profile individuals, such as senior executives, CEOs, or government officials, within an organization. The objective is often to gain access to highly sensitive corporate data or to authorize significant financial transactions. This attack vector is defined by its target, not the communication medium, and a general bank account scam via text message does not fit this executive-level targeting.
- ✗
Vishing
Why it's wrong here
Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack that utilizes telephone calls to manipulate individuals into revealing personal, financial, or account information. Attackers often employ Caller ID spoofing to impersonate legitimate organizations, creating a sense of urgency or authority. Since the scenario explicitly states a "text message," vishing, which relies on voice communication, is an incorrect classification.
- ✓
SMiShing
Why this is correct
SMiShing is the precise term for a phishing attack conducted via Short Message Service (SMS) text messages. In this method, attackers send deceptive text messages, often containing malicious links or requests for personal information, to mobile phone users. The goal is to trick recipients into clicking links that install malware, redirect to fraudulent websites, or directly provide sensitive data, perfectly matching the described scenario of a text message claiming bank account issues.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.