220-1102 Security Practice Question
A user reports receiving multiple phishing emails that appear to come from the company's CEO. The emails ask the user to wire money to an account for a business acquisition. Which type of social engineering attack is this?
⚠ Common exam trap
It's easy for candidates to confuse CEO fraud with generic phishing or vishing, but the specific impersonation of a C-level executive for financial gain is the defining characteristic that distinguishes it from other social engineering types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CEO fraud
CEO fraud is a type of spear phishing where the attacker impersonates a high-level executive (like the CEO) to trick an employee into performing a financial transfer. The email's request to wire money for a business acquisition is a classic indicator of this attack, as it exploits trust in authority and urgency to bypass normal verification procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CEO fraud
Why this is correct
CEO fraud, also known as business email compromise (BEC), is a targeted phishing variant where an attacker spoofs or compromises an executive's email account. The message typically pressures a finance employee to approve a time-sensitive wire transfer or payment, exploiting the authority and lack of verification. This matches the scenario, so it is the correct answer.
- ✗
Tailgating
Why it's wrong here
Tailgating is a physical security breach in which an attacker follows an authorized employee through a badge-controlled door or restricted entrance without presenting credentials. Because the scenario describes emails arriving in an inbox, tailgating cannot be the correct answer; it has no logical connection to deceptive messages or financial fraud.
- ✗
Shoulder surfing
Why it's wrong here
Shoulder surfing involves covertly watching a victim's monitor, keyboard, or documents to capture passwords, PINs, or confidential data in person. It is a direct observation attack that requires proximity, not an email-based social engineering technique, so it does not explain phishing messages purporting to come from company leadership.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is social engineering conducted over a telephone call or VoIP system, where the attacker poses as a trusted entity to extract personal details or credentials. Since the threat is transmitted via email rather than through an interactive voice conversation, vishing is an incorrect option here.
Go deeper
Related to this question
Learn chapter
Social Engineering for A+
Key term
Spear phishing
Spear phishing is a targeted cyberattack in which a criminal sends a fraudulent email that appears to come from a trusted source, aiming to trick a specific person or organization into revealing sensitive data or installing malware.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.