Courseiva
Malware, Social Engineering and Network AttackseasyMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

A user receives an email claiming to be from their bank, asking them to click a link and verify their account credentials. The email contains spelling errors and the link points to a suspicious domain. What type of social engineering attack is this?

⚠ Common exam trap

Test-takers frequently confuse 'phishing' with 'spear phishing' because both involve email, but the key differentiator is the level of targeting—phishing is mass and generic, while spear phishing is personalized and researched.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing

This scenario describes a mass, unsolicited email with generic content and a suspicious link, which is the classic definition of phishing. Phishing is a social engineering attack that uses deceptive emails to trick recipients into revealing sensitive information, such as credentials, by impersonating a trusted entity. The presence of spelling errors and a suspicious domain are common indicators of a phishing attempt, not a targeted attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vishing

    Why it's wrong here

    Vishing is a specific form of social engineering that exclusively leverages voice communication, typically over the telephone, to trick individuals into divulging sensitive information or performing actions. Unlike the scenario described, which involves an email as the initial contact vector, vishing attacks rely on verbal manipulation, often impersonating legitimate entities like banks or technical support to create a sense of urgency or trust. The absence of a voice call in the question immediately disqualifies vishing as the correct attack method.

  • Whaling

    Why it's wrong here

    Whaling is a highly targeted form of phishing specifically aimed at high-profile individuals within an organization, such as CEOs, CFOs, or other senior executives. These attacks are meticulously crafted with personalized content, often leveraging extensive research to impersonate legitimate business communications and trick the target into authorizing significant financial transfers or revealing critical corporate secrets. The question describes an email sent to 'a user,' implying a general target rather than a specific, high-value executive, thus not fitting the definition of whaling.

  • Spear phishing

    Why it's wrong here

    Spear phishing involves a highly customized attack targeting a specific individual or organization, where the attacker has conducted prior research to tailor the email's content, making it appear highly credible and relevant to the recipient. This personalization often includes mentioning specific projects, colleagues, or personal details to build trust and bypass skepticism. The scenario describes a generic email claiming to be from a bank sent to 'a user,' without any indication of specific personalization or prior research into that particular user, which is a hallmark of spear phishing.

  • Phishing

    Why this is correct

    Phishing is a broad social engineering technique characterized by mass-distributed, generic fraudulent communications, typically via email, designed to trick recipients into revealing sensitive information like login credentials, credit card numbers, or installing malware. These attacks often impersonate well-known entities such as banks, social media platforms, or online services, using urgent or alarming language to prompt immediate action. The email described, claiming to be from a bank and likely seeking credentials from a general user, perfectly aligns with the characteristics of a classic phishing campaign.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.