Pretexting: Fabricating a Scenario to Manipulate Help Desk
An attacker calls a company's help desk, pretending to be a new employee who forgot his username and password. The attacker provides some employee details gleaned from social media and convinces the help desk to reset the password. Which social engineering technique is being used?
Quick Answer
The answer is pretexting, the correct social engineering technique because the attacker fabricates a detailed scenario—posing as a new employee—to manipulate the help desk into resetting credentials. Pretexting relies on building a believable story, often using pretexting social engineering help desk tactics where the attacker gathers personal details from social media to establish false legitimacy. On the Certified Ethical Hacker CEH exam, this tests your ability to distinguish pretexting from similar attacks like phishing or baiting; a common trap is confusing it with impersonation, but pretexting always involves a constructed narrative rather than just assuming a role. Remember that pretexting is about the *story*—the attacker invents a context, not just a title. A useful memory tip: think “pretext equals pretext” as in the script or excuse used to gain trust, and on the help desk, any unsolicited request for password resets should trigger verification protocols.
⚠ Common exam trap
Watch out — candidates often confuse pretexting with baiting because both involve deception, but baiting relies on a lure (e.g., 'free movie download') while pretexting relies on a fabricated scenario (e.g., 'I am a new employee').
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pretexting
Pretexting is a social engineering technique where the attacker fabricates a scenario (pretext) to manipulate the target into performing an action. In this case, the attacker pretends to be a new employee, using details from social media to establish credibility, and convinces the help desk to reset credentials. This is a classic example of pretexting because the entire interaction is based on a false identity and fabricated story.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tailgating
Why it's wrong here
Tailgating is physically following an authorised person through a secured door without credentials; this scenario involves a telephone call and a password reset, with no physical access. Tailgating would be correct if the attacker entered a restricted area behind an employee.
- ✗
Quid pro quo
Why it's wrong here
Quid pro quo offers a service or benefit in exchange for information or access; this caller offers nothing, instead impersonating a new employee and exploiting help desk trust. Quid pro quo would fit an attacker posing as IT support offering help in return for credentials.
- ✗
Baiting
Why it's wrong here
Baiting lures a victim with a promised item or curiosity, such as infected media or downloads; here the attacker impersonates an employee by phone using harvested details. Baiting would be correct for a physical or digital lure, not voice impersonation of a new hire.
- ✓
Pretexting
Why this is correct
Pretexting is the fabrication of a believable scenario or identity to manipulate the target into complying. The attacker invents a new-employee story, reinforces it with harvested employee details, and thereby convinces the help desk to reset credentials, exploiting trust in the invented pretext.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a social engineering engagement, an attacker calls an employee pretending to be from IT support and asks for their password to perform a system update. Which social engineering technique is being employed?
medium- A.Phishing
- ✓ B.Pretexting
- C.Quid pro quo
- D.Vishing
Why B: Pretexting is the correct answer because the attacker fabricates a scenario (pretext) by impersonating IT support to create a false sense of authority and urgency, thereby manipulating the employee into revealing their password. This technique relies on a fabricated story rather than a technical exploit, distinguishing it from other social engineering methods.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.