CEH Practice Question: Malware, Social Engineering and Network Attacks
During a social engineering engagement, an attacker calls an employee pretending to be from IT support and asks for their password to perform a system update. Which social engineering technique is being employed?
⚠ Common exam trap
Many candidates confuse pretexting with vishing because both involve phone calls, but the CEH exam distinguishes them by the presence of a fabricated scenario (pretext) versus a simple voice-based phishing attempt without an elaborate backstory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is the correct answer because the attacker fabricates a scenario (pretext) by impersonating IT support to create a false sense of authority and urgency, thereby manipulating the employee into revealing their password. This technique relies on a fabricated story rather than a technical exploit, distinguishing it from other social engineering methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing is a widespread social engineering technique primarily executed through fraudulent electronic communications, most commonly emails, designed to deceive recipients. Its objective is to trick individuals into divulging sensitive information, such as login credentials or financial data, or to deploy malicious software. The key distinction here is the medium; while the goal of deception is shared, classic phishing relies on text-based or visual lures rather than a direct, interactive voice call.
- ✓
Pretexting
Why this is correct
Pretexting involves the creation of a convincing, fabricated scenario or "pretext" to manipulate a target into revealing confidential information or performing a specific action. In this type of social engineering engagement, the attacker constructs a plausible backstory, such as impersonating IT support or a vendor, to establish trust and extract desired details directly from the target over the phone. This method precisely aligns with an attacker calling someone with a specific, made-up story to achieve their objective.
- ✗
Quid pro quo
Why it's wrong here
Quid pro quo, meaning "something for something," is a social engineering tactic where an attacker offers a small service, benefit, or reward in exchange for information or access. An example might be offering "free technical support" or a prize in return for login credentials or personal data. The scenario described does not involve a transactional exchange where the target perceives receiving a benefit; instead, it's a direct deception without an explicit trade.
- ✗
Vishing
Why it's wrong here
Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack conducted over the telephone, aiming to trick individuals into revealing sensitive information. While the scenario involves a voice call, vishing often encompasses a broader range of voice-based attacks, including automated calls or generic impersonations of legitimate entities. Pretexting, however, is a more specific technique within vishing, focusing on the meticulous construction of a believable, fabricated narrative to manipulate the target, making it a more precise description for a targeted engagement with a specific story.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.