Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security analyst notices that the CFO of the company received an email that appears to be from the company's external legal counsel. The email requests that the CFO click a link to review an urgent contract. The email address is spoofed to look similar to the real one. Which type of social engineering attack is this?

⚠ Common exam trap

Many exam-takers confuse 'spear phishing' (targeted but not necessarily executive) with 'whaling' (specifically targeting senior executives like the CFO), so they pick spear phishing because it sounds more specific than phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Whaling

Whaling is a targeted form of phishing that specifically goes after high-profile executives (like the CFO) or individuals with access to sensitive data. The attack uses a spoofed email address mimicking external legal counsel and a sense of urgency to trick the executive into clicking a malicious link, making it whaling rather than generic phishing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Generic phishing casts a broad net, sending the same template to thousands of users without prior targeting. This email was deliberately crafted for the CFO, implying reconnaissance and personalization that mass phishing lacks. Because the payload and pretext are tailored to an executive rather than sprayed indiscriminately, classifying it as plain phishing understates the precision and risk.

  • ✗

    Spear phishing

    Why it's wrong here

    Spear phishing does involve personalized messages to particular individuals, but it does not inherently denote executive rank. Whaling is the recognized subcategory of spear phishing when the victim is a C-level officer, such as a CFO, whose access and financial authority make the attack especially consequential. Since the scenario specifies the CFO and a credential-harvesting link, whaling is the more accurate and specific label.

  • ✓

    Whaling

    Why this is correct

    Whaling manipulates a senior executive's gatekeeping and authority, often using urgent, seemingly legitimate correspondence that references business operations or financial oversight. Because the CFO can approve payments or access sensitive financial systems, the malicious link is designed to bypass normal user-level defenses, potentially enabling fraudulent wire transfers or credential compromise. This scenario exactly matches the whaling pattern: a high-value, targeted executive receiving a professional-looking email with a malicious link.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is a social engineering attack delivered via SMS or other text-messaging platforms, often using shortened URLs, fake package-delivery alerts, or bank verification texts. The vector in this incident is email, not a mobile messaging channel, so the delivery mechanism eliminates smishing as a valid classification. Even if the email were opened on a mobile device, the attack remains an email-based attack, and smishing specifically requires the text message channel.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.