Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives an email that appears to be from the company's CEO. The email states that the CEO is in a meeting and urgently needs the user to purchase several gift cards and email the redemption codes to the CEO. The email address is slightly different from the CEO's actual email address (e.g., ceo@cornpany.com instead of ceo@company.com). The user suspects this is a social engineering attack. Which type of social engineering attack is this?

⚠ Common exam trap

Many candidates confuse 'spear phishing' with 'whaling' because both involve impersonation of a high-level figure, but whaling specifically targets the executive themselves, not an employee being tricked by a fake executive email.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Spear phishing

This is a spear phishing attack because the email is specifically targeted at a single individual (the user) and is personalized using the CEO's identity and context (urgent meeting, gift cards). The slight domain spoofing (ceo@cornpany.com vs. ceo@company.com) is a classic spear phishing technique to bypass basic email filters and trick the recipient into trusting the sender. Unlike generic phishing, spear phishing uses reconnaissance to craft a believable, targeted lure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad, untargeted attack that sends the same generic message to thousands of users, relying on volume and urgency (e.g., 'your account has been suspended') rather than personal knowledge of the recipient. This email was tailored to a specific user and impersonates the company's CEO, which indicates the attacker performed reconnaissance and customized the lure. Therefore, 'phishing' alone is too imprecise; the targeted, personalized nature makes this spear phishing.

  • ✓

    Spear phishing

    Why this is correct

    Spear phishing is the correct classification because the email incorporates personal context—such as the recipient's identity, company role, and the impersonation of a specific trusted figure (the CEO). The attacker likely gathered details from corporate websites, LinkedIn, or prior breaches to craft a convincing, tailored message that bypasses generic defenses. Unlike mass phishing, spear phishing targets a particular individual or a small, selected group, which matches this scenario exactly.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is a specialized subtype of spear phishing that specifically targets high-ranking executives like the CEO, CFO, or other C-suite leaders whose approval authority can authorize large financial transfers or expose board-level secrets. In this event, the victim is described simply as 'a user' with no indication of executive rank or elevated privileges, so the victim profile does not align with whaling. Even though the sender impersonates the CEO, whaling is defined by who the victim is, not by who the attacker pretends to be.

  • ✗

    Vishing

    Why it's wrong here

    Vishing (voice phishing) uses phone calls, VoIP systems, or voicemail messages to trick the target into disclosing credentials, installing remote-access software, or performing unauthorized actions. Because the attack described here is delivered via email, the communication channel directly rules out vishing. If the scam had instead used a live phone call or a spoofed voicemail claiming to be the CEO, it would be vishing—but an email message cannot be classified as voice-based social engineering.

Go deeper

Related to this question

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.