CEH Practice Question: Malware, Social Engineering and Network Attacks
Which tool is specifically designed to automate social engineering attacks, such as phishing and credential harvesting?
⚠ Common exam trap
Many candidates confuse Metasploit's broad exploitation capabilities with SET's specialized social engineering automation, forgetting that SET is the dedicated tool for phishing and credential harvesting in the CEH toolkit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SET
The Social Engineering Toolkit (SET) is an open-source Python-driven framework specifically designed to automate social engineering attacks, including phishing campaigns, credential harvesting via cloned websites, and spear-phishing payloads. It integrates with Metasploit for payload delivery but is distinct in its focus on manipulating human behavior rather than exploiting technical vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark captures and analyses packet-level traffic for troubleshooting and forensic inspection; it cannot craft phishing emails or clone credential-harvesting pages. It would be correct for inspecting captured network protocols and reconstructing sessions, not for automating social engineering campaigns.
- ✗
Nmap
Why it's wrong here
Nmap performs network discovery and port scanning, mapping hosts and services; it contains no phishing campaign engine, credential-harvesting templates or email lures. It would be the right choice for enumerating live hosts and open ports during reconnaissance, not for automating social engineering attacks.
- ✗
Metasploit
Why it's wrong here
Metasploit delivers exploit modules and payloads against discovered vulnerabilities; it does not generate phishing lures, spoofed landing pages or credential-capture workflows. It would be correct for exploitation and post-exploitation after initial access, not for automating the social engineering stage itself.
- ✓
SET
Why this is correct
The Social-Engineer Toolkit automates credential-harvesting attacks, cloning login pages and combining email templates with cloned sites to capture submitted credentials. This directly satisfies the requirement for a tool purpose-built to automate phishing and harvesting, rather than general exploitation frameworks.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.