Courseiva
Security Concepts →hardMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is reviewing a suspicious email reported by a user. The email appears to come from the CEO and requests an urgent wire transfer. The analyst examines the email headers and notices that the 'From' address is spoofed and the 'Reply-To' address is different from the 'From' address. The email also contains a link to a credential-harvesting page. Which type of attack is this?

⚠ Common exam trap

The trap here is labeling any fraudulent email as phishing; BEC is a specific subtype that involves impersonating executives to commit financial fraud, often without malware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business email compromise (BEC)

The email impersonates the CEO and requests an urgent wire transfer, which is the hallmark of business email compromise (BEC). BEC attacks often involve spoofed sender addresses and may include links to credential-harvesting sites. While it is a form of phishing, BEC specifically targets financial transactions and is a distinct category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing is a targeted phishing attack against specific individuals or organizations. Although this attack is targeted, the defining characteristic here is the impersonation of an executive to commit financial fraud, which is BEC. Spear phishing may be used in BEC, but the term BEC is more precise for this scenario.

  • ✓

    Business email compromise (BEC)

    Why this is correct

    BEC is a sophisticated scam where attackers impersonate executives or trusted partners to trick employees into transferring funds or revealing sensitive information. The scenario describes a spoofed CEO email requesting an urgent wire transfer, which is a classic BEC attack. The mismatched Reply-To and credential-harvesting link further support this classification.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is a type of phishing specifically targeting high-profile individuals like CEOs or CFOs. In this scenario, the attacker is impersonating the CEO to target an employee, not targeting the CEO directly. Therefore, whaling does not fit; the attack is BEC, which often impersonates executives to deceive lower-level employees.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad term for fraudulent emails that attempt to steal credentials or deliver malware. While this email is a form of phishing, the specific scenario of impersonating a CEO to request a wire transfer is more accurately classified as business email compromise, which is a targeted subtype of phishing. Phishing alone does not capture the financial fraud aspect.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.