Courseiva

Using SET for Phishing: Clone Websites and Steal Credentials

An attacker uses the Social Engineering Toolkit (SET) to clone a legitimate website and send a malicious link to employees. When an employee clicks the link, they are prompted to enter their credentials. Which attack is this?

Quick Answer

The answer is phishing. This is correct because the Social Engineering Toolkit (SET) is specifically designed to automate credential harvesting attacks by cloning legitimate websites and serving them to victims via malicious links; when the target enters their credentials on the cloned page, those credentials are captured and sent to the attacker. On the Certified Ethical Hacker CEH exam, this scenario tests your ability to distinguish phishing from other social engineering attacks like spear phishing or vishing—the key differentiator here is the use of a cloned website to trick the user into voluntarily submitting login details. A common trap is confusing this with a man-in-the-middle attack, but SET’s phishing module does not intercept live traffic; it simply presents a fake login page. Remember the mnemonic “SET Sends a Phony Clone” to recall that SET’s primary phishing function relies on website cloning for credential theft.

⚠ Common exam trap

The CEH exam often tests the distinction between generic phishing and spear phishing, where the trap is assuming any targeted employee list automatically qualifies as spear phishing, even without personalized content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

The Social Engineering Toolkit (SET) is used to clone a legitimate website and capture credentials via a malicious link. This is a classic phishing attack because it involves sending a fraudulent communication (the link) that mimics a trusted entity to trick victims into revealing sensitive information. The attack does not rely on SMS (SMiShing), voice calls (Vishing), or targeted personalization (Spear phishing) beyond the generic employee group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SMiShing

    Why it's wrong here

    SMiShing is credential harvesting delivered by SMS text message, whereas this scenario uses a cloned website link sent to employees, which is phishing. It is tempting because both are social-engineering credential-theft variants, and SMiShing would be correct had the lure arrived as a text message rather than a link.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing targets specific individuals with personalised content, but the scenario describes a generic cloned website link sent to multiple employees without tailoring the message or pretext to any single recipient. This attack is tempting because spear phishing does involve credential harvesting via deceptive links; it would be correct if the attacker had researched each employee’s role or interests to craft individualised lures, rather than broadcasting the same cloned page to all.

  • ✗

    Vishing

    Why it's wrong here

    Vishing is voice-based social engineering conducted over telephone calls, not a cloned website capturing credentials. It is tempting because it is another SET-supported credential-theft technique, and vishing would be correct if the attacker had telephoned employees and talked them into revealing credentials verbally.

  • ✓

    Phishing

    Why this is correct

    Cloning a legitimate site and harvesting credentials via a sent link is credential phishing. The Social Engineering Toolkit automates the fake login page, but the attack category remains phishing, defined by deceptive messaging that induces victims to surrender sensitive information.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An attacker uses the Social Engineering Toolkit (SET) to send a malicious email to employees of a company, claiming to be from IT support and urging them to click a link to reset their password. Which social engineering attack is being performed?

medium
  • A.Vishing
  • ✓ B.Phishing
  • C.Baiting
  • D.SMiShing

Why B: The Social Engineering Toolkit (SET) is used to craft and send fraudulent emails that appear to come from a trusted source (IT support), urging the recipient to click a link and enter credentials. This is a classic phishing attack because it uses email as the vector and relies on deception to steal sensitive information. Unlike vishing (voice) or SMiShing (SMS), the attack is executed via email, which is the defining characteristic of phishing.

Variation 2. Which tool is specifically designed to automate social engineering attacks, such as phishing and credential harvesting?

easy
  • A.Wireshark
  • B.Nmap
  • C.Metasploit
  • ✓ D.SET

Why D: The Social Engineering Toolkit (SET) is an open-source Python-driven framework specifically designed to automate social engineering attacks, including phishing campaigns, credential harvesting via cloned websites, and spear-phishing payloads. It integrates with Metasploit for payload delivery but is distinct in its focus on manipulating human behavior rather than exploiting technical vulnerabilities.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.