Courseiva
Malware, Social Engineering and Network AttacksmediumMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

An attacker uses the Social Engineering Toolkit (SET) to send a malicious email to employees of a company, claiming to be from IT support and urging them to click a link to reset their password. Which social engineering attack is being performed?

⚠ Common exam trap

The CEH exam often tests the distinction between phishing, vishing, and SMiShing by focusing on the delivery medium (email vs. voice vs. SMS), so candidates must remember that 'phishing' specifically refers to email-based social engineering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing

The Social Engineering Toolkit (SET) is used to craft and send fraudulent emails that appear to come from a trusted source (IT support), urging the recipient to click a link and enter credentials. This is a classic phishing attack because it uses email as the vector and relies on deception to steal sensitive information. Unlike vishing (voice) or SMiShing (SMS), the attack is executed via email, which is the defining characteristic of phishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vishing

    Why it's wrong here

    Vishing is a social engineering technique that exclusively utilizes voice communication, typically over phone calls or Voice over IP (VoIP), to manipulate individuals. Attackers often impersonate trusted entities like banks or government agencies, coercing victims into revealing sensitive personal or financial information, or performing actions under false pretenses. This method relies on real-time interaction and vocal cues, distinguishing it from text-based attacks.

  • Phishing

    Why this is correct

    Phishing is a prevalent cyberattack where adversaries employ deceptive emails to trick recipients into divulging confidential information or executing malicious actions. The Social Engineering Toolkit (SET) is frequently used to craft convincing fake login pages or deliver malware via email attachments, making it a classic vector for credential harvesting or system compromise. This method leverages trust and urgency to bypass security awareness and technical controls.

  • Baiting

    Why it's wrong here

    Baiting is a physical social engineering tactic where an attacker leaves a malware-infected device, such as a USB flash drive or CD, in a public location where a curious victim is likely to find and use it. The lure often involves labeling the device with enticing names like 'Company Payroll' or 'Confidential Data' to maximize the chance of discovery and insertion into a target system. Once plugged in, the malicious payload executes, compromising the victim's machine or network.

  • SMiShing

    Why it's wrong here

    SMiShing is a specialized form of phishing that specifically targets mobile phone users through Short Message Service (SMS) or text messages. Attackers send fraudulent messages, often impersonating banks, delivery services, or government agencies, containing malicious links designed to steal credentials or install malware. Alternatively, these messages might prompt the victim to call a premium-rate or fraudulent number, exploiting the immediate nature and perceived authenticity of text communication.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.