Study for the Ethical Hacking Essentials Test. Explore interactive flashcards and multiple-choice questions with hints and explanations. Prepare thoroughly and boost your exam readiness!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


What type of malware distribution technique impersonates legitimate institutions to steal credentials?

  1. Social engineering

  2. Spear-phishing sites

  3. Malvertising

  4. Decoy applications

The correct answer is: Spear-phishing sites

The correct answer involves spear-phishing sites, which are specifically designed to impersonate legitimate institutions, such as banks or popular online services, to trick users into providing their credentials. These sites often closely mimic the appearance and functionality of the authentic sites, including logos, content, and design elements to enhance their credibility and lure victims. Users may receive communications purporting to be from these institutions, directing them to these phishing sites where they are prompted to enter sensitive information. By exploiting the trust that individuals have in well-known organizations, spear-phishing sites effectively enable attackers to steal personal and financial data. In the context of other options, social engineering encompasses a broader category of manipulative tactics used to exploit human psychology, making it applicable but not limited to online credential theft. Malvertising refers to malicious ads designed to spread malware rather than directly impersonate institutions. Decoy applications could potentially mislead users, but they typically do not impersonate established institutions in the same direct manner as spear-phishing sites.