Courseiva
Malware, Social Engineering and Network AttackseasyMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

An employee receives an SMS message that claims to be from the IT department, asking the employee to click a link to verify their email account. Which social engineering attack is this?

⚠ Common exam trap

A common mix-up: candidates confuse 'phishing' as a generic term for all social engineering attacks, but the CEH exam distinguishes SMiShing as the specific term for SMS-based phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SMiShing

C is correct because SMiShing (SMS phishing) specifically uses SMS text messages as the attack vector to deliver a malicious link or request, exactly as described in the scenario. Unlike email-based phishing, SMiShing exploits the trust users place in text messages and often bypasses email security filters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vishing

    Why it's wrong here

    Vishing, a portmanteau of 'voice' and 'phishing,' is a social engineering attack that leverages voice communication, typically over the telephone. Attackers impersonate trusted entities to manipulate victims into revealing sensitive information, such as bank details or login credentials, or performing actions like transferring money. This method relies on real-time interaction and vocal cues to build rapport and urgency, distinguishing it from text-based attacks like the one described in the question.

  • Phishing

    Why it's wrong here

    Phishing is a broad category of cyberattack where adversaries attempt to trick individuals into divulging sensitive information, often through deceptive electronic communications. While it primarily refers to email-based attacks, where malicious links or attachments are common, the term broadly encompasses attempts to acquire data by masquerading as a trustworthy entity. However, for attacks specifically utilizing SMS messages, a more precise term exists to differentiate the vector and its unique characteristics.

  • SMiShing

    Why this is correct

    SMiShing, a portmanteau of 'SMS' and 'phishing,' is a specific type of social engineering attack that utilizes text messages to deceive recipients. Attackers send fraudulent SMS messages, often containing malicious links that lead to credential harvesting sites or malware downloads, or instructing victims to call a fraudulent number. This method exploits the trust users place in their mobile devices and the immediacy of text messages to prompt quick, unthinking responses, making it the direct answer for an SMS-based attack.

  • Whaling

    Why it's wrong here

    Whaling is a highly targeted form of spear phishing specifically aimed at high-profile individuals within an organization, such as C-level executives or senior management. These sophisticated attacks are meticulously crafted, often leveraging publicly available information to create highly personalized and convincing pretexts. The objective is typically to gain access to sensitive corporate data, initiate large financial transfers, or compromise critical systems, making it distinct from attacks targeting general employees.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.