Courseiva
Vulnerability Analysis and System HackingmediumMatchingObjective-mapped

CEH Vulnerability Analysis and System Hacking Practice Question

Match each type of attack to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Social engineering via deceptive emails

Intercepting communication between two parties

Inserting malicious SQL queries into input fields

Overwhelming a system to make it unavailable

Associating attacker's MAC with victim's IP

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing: A broad term for social engineering attacks that use fraudulent emails or websites to trick individuals into revealing sensitive information.

The correct matches are Phishing with its broad definition, Spear Phishing with targeted definition, and Whaling with high-profile target definition. Common confusions: Vishing is voice-based, Smishing is SMS-based; also targeted phishing is spear phishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing: A broad term for social engineering attacks that use fraudulent emails or websites to trick individuals into revealing sensitive information.

    Why this is correct

    Phishing is a widespread social engineering technique where attackers impersonate legitimate entities to deceive individuals. This typically involves sending fraudulent emails or directing victims to fake websites designed to harvest sensitive credentials, financial data, or other personal information. Its broad scope means it often targets a large, undifferentiated audience, hoping a percentage will fall victim to the deceptive lures.

  • Spear Phishing: A targeted form of phishing directed at a specific individual or organization.

    Why this is correct

    Spear phishing represents a more sophisticated and highly targeted form of phishing, specifically aimed at a particular individual or organization. Attackers meticulously research their targets to craft personalized and convincing messages, often leveraging publicly available information or prior data breaches. The goal is to exploit trust and relevance, making the fraudulent communication appear legitimate and compelling to the intended victim, thereby increasing the likelihood of success.

  • Whaling: A type of spear phishing that targets high-profile individuals like executives.

    Why this is correct

    Whaling is a specialized subset of spear phishing that exclusively targets high-value individuals within an organization, such as CEOs, CFOs, or other senior executives. These attacks are meticulously crafted, often impersonating legal counsel, government agencies, or other high-authority figures to induce the target to authorize large financial transfers or divulge critical corporate secrets. The substantial potential impact of compromising such a high-profile individual makes whaling a particularly lucrative and dangerous threat.

  • Vishing: A targeted form of phishing directed at a specific individual.

    Why it's wrong here

    The provided definition incorrectly describes spear phishing, not vishing. Vishing, a portmanteau of 'voice' and 'phishing,' is a social engineering attack conducted over the telephone, where attackers impersonate trusted entities to manipulate victims into divulging sensitive information or performing actions. This often involves using techniques like caller ID spoofing and pre-recorded messages to create a sense of urgency or authority, making it a distinct vector from email or website-based attacks.

  • Smishing: Voice phishing using phone calls.

    Why it's wrong here

    The given definition inaccurately describes vishing, not smishing. Smishing refers to phishing attacks delivered via SMS (Short Message Service) text messages, where attackers send fraudulent messages designed to trick recipients into clicking malicious links, calling premium-rate numbers, or revealing personal data. These messages often mimic legitimate alerts from banks, delivery services, or government agencies, exploiting the ubiquitous nature of mobile communication.

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.