easyMultiple ChoiceObjective-mapped
PT0-002 Practice Question: A penetration tester is planning a social…
A penetration tester is planning a social engineering campaign against a corporation. The goal is to trick the CEO into revealing sensitive information. Which type of attack should the tester use?
⚠ Common exam trap
CompTIA often tests the distinction between spear phishing and whaling, where the trap is that candidates choose spear phishing because it is a broader term, but the question's focus on a CEO specifically requires the more precise 'whaling' classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whaling
Whaling is a targeted form of phishing that specifically focuses on high-profile individuals, such as the CEO. In this scenario, the goal is to trick the CEO into revealing sensitive information, making whaling the correct choice because it is designed to impersonate trusted entities or create urgent scenarios to deceive senior executives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing (voice phishing) uses phone calls or VoIP with caller-ID spoofing to trick a user into disclosing credentials, MFA codes, or sensitive data. While a vishing campaign can absolutely be aimed at a CEO, the term describes the medium and tactic, not the executive-level target. In contrast, 'whaling' specifically denotes attacks directed at senior executives, so vishing is too broad and imprecise for this scenario.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted phishing attack that is tailored to a specific individual using OSINT-gathered details like job role, projects, or personal interests. It is accurate to say a CEO could be spear-phished, but the term does not indicate that the victim is a senior executive; any employee can be a spear-phishing target. Whaling is the specialized subset for C-suite and high-value executives, so spear phishing lacks the precise semantic focus the question asks for.
- ✗
Pharming
Why it's wrong here
Pharming is a non-social-engineering attack that redirects victims' traffic by poisoning DNS caches, altering hosts files, or compromising a router so that a legitimate domain resolves to a malicious server. The victim is manipulated indirectly through infrastructure, not through persuasive communication, and the attacker often does not even know who the victim is. Because the campaign specifically targets a named CEO, pharming does not fit the targeting logic and is not a social engineering technique in the same category as whaling.
- ✓
Whaling
Why this is correct
Whaling is the established term for a spear-phishing attack aimed at high-level executives such as a CEO, CFO, or other senior officers. The attacker crafts pretexts like legal subpoenas, urgent board communications, or financial transaction requests that exploit the executive's authority, busy schedule, and access to critical systems or funds. In a pen-test scenario targeting a CEO, whaling is the correct label because it names both the technique and the specific victim class.
Go deeper
Related to this question
About these practice questions
This PT0-003 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.