nerdexam
EC-Council

312-50V13 · Question #394

Ben purchased a new smartphone and received some updates on it through the OTA method. He received two messages: one with a PIN from the network operator and another asking him to enter the PIN…

The correct answer is A. Advanced SMS phishing. This scenario describes an Advanced SMS phishing attack, where an attacker leverages legitimate-looking SMS messages to trick a user into providing a sensitive PIN, leading to compromise or abnormal device behavior.

Submitted by javi_es· Mar 6, 2026Hacking Mobile Platforms

Question

Ben purchased a new smartphone and received some updates on it through the OTA method. He received two messages: one with a PIN from the network operator and another asking him to enter the PIN received from the operator. As soon as he entered the PIN, the smartphone started functioning in an abnormal manner. What is the type of attack performed on Ben in the above scenario?

Options

  • AAdvanced SMS phishing
  • BBypass SSL pinning
  • CPhishing
  • DTap 'n ghost attack

How the community answered

(41 responses)
  • A
    83% (34)
  • B
    2% (1)
  • C
    5% (2)
  • D
    10% (4)

Why each option

This scenario describes an Advanced SMS phishing attack, where an attacker leverages legitimate-looking SMS messages to trick a user into providing a sensitive PIN, leading to compromise or abnormal device behavior.

AAdvanced SMS phishingCorrect

The scenario involves two SMS messages, one seemingly legitimate from the network operator and another malicious one prompting for the PIN, leading to abnormal phone behavior. This is an advanced form of SMS phishing (smishing) designed to bypass initial user skepticism by using context from a legitimate communication.

BBypass SSL pinning

Bypass SSL pinning refers to techniques used to circumvent the security mechanism that prevents man-in-the-middle attacks on HTTPS connections to specific servers, which is not applicable to an SMS-based PIN attack.

CPhishing

Phishing is a general term for deceptive attempts to acquire sensitive information, but "Advanced SMS phishing" is a more specific and accurate description for this multi-step, context-aware SMS attack.

DTap 'n ghost attack

"Tap 'n ghost attack" is not a widely recognized or standard term for a mobile phone attack in cybersecurity; it seems to be a fabricated or niche term.

Concept tested: Mobile phishing (Advanced Smishing)

Source: https://www.cisa.gov/news-events/news/cisa-warns-increase-smishing-attacks

Topics

#SMS phishing#smishing#mobile security#social engineering

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice