200-201 Security Concepts Practice Question
A security analyst is reviewing a suspicious email reported by a user. The email appears to come from the CEO and requests an urgent wire transfer. The analyst examines the email headers and notices that the 'From' address is spoofed and the 'Reply-To' address is different from the 'From' address. The email also contains a link to a credential-harvesting page. Which type of attack is this?
⚠ Common exam trap
The trap here is labeling any fraudulent email as phishing; BEC is a specific subtype that involves impersonating executives to commit financial fraud, often without malware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business email compromise (BEC)
The email impersonates the CEO and requests an urgent wire transfer, which is the hallmark of business email compromise (BEC). BEC attacks often involve spoofed sender addresses and may include links to credential-harvesting sites. While it is a form of phishing, BEC specifically targets financial transactions and is a distinct category.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted phishing attack against specific individuals or organizations. Although this attack is targeted, the defining characteristic here is the impersonation of an executive to commit financial fraud, which is BEC. Spear phishing may be used in BEC, but the term BEC is more precise for this scenario.
- ✓
Business email compromise (BEC)
Why this is correct
BEC is a sophisticated scam where attackers impersonate executives or trusted partners to trick employees into transferring funds or revealing sensitive information. The scenario describes a spoofed CEO email requesting an urgent wire transfer, which is a classic BEC attack. The mismatched Reply-To and credential-harvesting link further support this classification.
- ✗
Whaling
Why it's wrong here
Whaling is a type of phishing specifically targeting high-profile individuals like CEOs or CFOs. In this scenario, the attacker is impersonating the CEO to target an employee, not targeting the CEO directly. Therefore, whaling does not fit; the attack is BEC, which often impersonates executives to deceive lower-level employees.
- ✗
Phishing
Why it's wrong here
Phishing is a broad term for fraudulent emails that attempt to steal credentials or deliver malware. While this email is a form of phishing, the specific scenario of impersonating a CEO to request a wire transfer is more accurately classified as business email compromise, which is a targeted subtype of phishing. Phishing alone does not capture the financial fraud aspect.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.