SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst is investigating a phishing campaign that specifically targets senior executives in a company. The emails appear to come from the CEO and request urgent wire transfers to a fraudulent account. Which of the following best describes this type of attack?
⚠ Common exam trap
CompTIA often tests the distinction between whaling and spear phishing, where candidates mistakenly choose spear phishing because they overlook that whaling is a specific subtype targeting executives, not just any individual.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whaling
This attack is whaling because it specifically targets senior executives (the 'big fish') with a fraudulent email impersonating the CEO to request urgent wire transfers. Whaling is a form of phishing that focuses on high-profile individuals within an organization, leveraging their authority and access to sensitive financial operations. The attack exploits the trust and urgency associated with executive communications to bypass standard security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Whaling
Why this is correct
Whaling is a highly targeted form of spear phishing that focuses specifically on senior executives, such as CEOs, CFOs, or other high-value individuals with privileged access to financial systems or sensitive corporate data. Attackers craft meticulously researched emails that impersonate trusted internal or external authorities, often invoking legal, compliance, or urgent transactional pretexts to pressure the victim into actions like wire transfers or credential disclosure. Unlike generic spear phishing, which may target any individual with specific attributes, whaling is defined by the executive-level target and the disproportionate potential impact, making it a distinct and more dangerous subtype.
- ✗
Spear phishing
Why it's wrong here
Incorrect. Spear phishing is a targeted phishing attack aimed at a specific individual or group, but it does not necessarily focus on executives. The attack in the question is specifically directed at senior executives, making whaling a more accurate term.
- ✗
Vishing
Why it's wrong here
Vishing, short for voice phishing, is a social engineering attack conducted over voice communication channels such as telephone calls or VoIP. Instead of using email, attackers impersonate legitimate entities like bank representatives, IT helpdesk staff, or government agencies, often using caller ID spoofing to appear trustworthy. They exploit the immediacy and personal interaction of a phone call to create a false sense of urgency, coercing victims into revealing personal information, credentials, or even performing wire transfers. The attack vector is audio, not email, so it requires different defensive measures such as verifying caller identity through independent channels and employee training on vishing tactics.
When this WOULD be correct
A question describing a phishing attack where the attacker calls a senior executive, impersonates the CEO, and requests an urgent wire transfer over the phone would make vishing the correct answer.
- ✗
Pharming
Why it's wrong here
Pharming is a cyberattack that manipulates the DNS resolution process or modifies local host files on a victim's machine to redirect traffic from a legitimate website to a fraudulent replica. It does not rely on deceptive emails or direct social engineering; instead, the victim is unknowingly sent to a malicious server even when they type the correct URL. This can occur server-side via DNS cache poisoning, or client-side via malware that alters the 'hosts' file. Because the user sees a familiar website and may have initiated the connection through a bookmarked or typed address, pharming bypasses many email-based phishing defenses and underscores the need for DNSSEC and endpoint protection.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓WhalingCorrect answer▾
Why this is correct
Whaling is a highly targeted form of spear phishing that focuses specifically on senior executives, such as CEOs, CFOs, or other high-value individuals with privileged access to financial systems or sensitive corporate data. Attackers craft meticulously researched emails that impersonate trusted internal or external authorities, often invoking legal, compliance, or urgent transactional pretexts to pressure the victim into actions like wire transfers or credential disclosure. Unlike generic spear phishing, which may target any individual with specific attributes, whaling is defined by the executive-level target and the disproportionate potential impact, making it a distinct and more dangerous subtype.
✗VishingWrong answer — click to see why▾
Why this is wrong here
Vishing is a voice-based phishing attack conducted over phone calls, not email. The scenario describes emails requesting wire transfers, which is a text-based attack, not voice.
★ When this WOULD be the correct answer
A question describing a phishing attack where the attacker calls a senior executive, impersonates the CEO, and requests an urgent wire transfer over the phone would make vishing the correct answer.
Why candidates choose this
Candidates may confuse the term 'vishing' with 'phishing' due to similar names, or mistakenly think any social engineering attack targeting executives is vishing, without recognizing the voice channel requirement.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.