CEH Practice Question: Malware, Social Engineering and Network Attacks
Which type of social engineering attack involves a malicious actor impersonating a legitimate organization in a voicemail message to trick the victim into revealing sensitive information?
⚠ Common exam trap
A common mix-up: candidates confuse vishing with SMiShing because both involve phishing via communication channels, but SMiShing uses SMS text messages while vishing uses voice calls or voicemail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vishing
Vishing (voice phishing) is the correct answer because it specifically involves using voice communication—such as a phone call or voicemail—to impersonate a legitimate organization and trick the victim into revealing sensitive information like passwords or credit card numbers. Unlike other social engineering attacks, vishing exploits the trust associated with voice interactions and often uses caller ID spoofing to appear as a trusted entity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SMiShing
Why it's wrong here
SMiShing is a social engineering attack that leverages Short Message Service (SMS) text messages to trick recipients. Attackers send fraudulent messages, often impersonating legitimate entities, to induce victims into clicking malicious links, downloading malware, or calling a fraudulent phone number. This method primarily relies on text-based communication, distinguishing it from attacks involving voice.
- ✗
Pharming
Why it's wrong here
Pharming is a type of cyberattack designed to redirect users from legitimate websites to fraudulent ones without their knowledge or consent. This is typically achieved through DNS cache poisoning or by modifying the victim's local hosts file, making it a technical manipulation of name resolution rather than a direct interactive deception involving voice communication. The user's browser is directed to a malicious site even if they type the correct URL.
- ✗
Baiting
Why it's wrong here
Baiting is a social engineering technique that entices victims with a tempting physical or digital "lure" to compromise their systems or data. This often involves leaving malware-infected USB drives in public places, hoping a curious individual will insert them, or offering enticing but malicious downloads like free movies or software. The attack relies on the victim's curiosity or greed, rather than direct voice communication.
- ✓
Vishing
Why this is correct
Vishing, a portmanteau of "voice" and "phishing," is a social engineering attack that utilizes voice communication, typically over telephone calls or Voice over IP (VoIP), to trick individuals. Attackers often impersonate trusted entities like banks, government agencies, or technical support to manipulate victims into revealing sensitive personal or financial information, or to perform actions like installing malicious software. Its defining characteristic is the direct, real-time vocal interaction with the target.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.