SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst is reviewing a suspicious email that was reported by an employee. The email appears to come from the company's CEO and asks the employee to urgently wire funds to a new vendor. The email address is slightly misspelled (e.g., `ceo@c0mpany.com` instead of `ceo@company.com`). The analyst confirms that the CEO did not send the email. Which type of attack is this?
⚠ Common exam trap
Many exam-takers confuse BEC with spear phishing or whaling; BEC specifically involves impersonating an executive to commit fraud, while whaling targets executives as victims.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business email compromise (BEC)
The email impersonates the CEO using a look-alike domain and requests an urgent wire transfer, which is the hallmark of business email compromise (BEC). BEC attacks often target employees with access to financial resources, leveraging authority and urgency. While it shares similarities with spear phishing and whaling, the specific impersonation of an executive for financial fraud is best classified as BEC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted phishing attack aimed at specific individuals, often using personalized information. While this email targets an employee, the key characteristic is the spoofed domain and the business email compromise (BEC) motive. Spear phishing may use similar tactics, but the specific impersonation of an executive for financial fraud is better classified as BEC, which is a subset of phishing but distinct in its objective.
- ✗
Vishing
Why it's wrong here
Vishing is voice phishing conducted over the phone, often using VoIP. This attack was delivered via email, not a phone call. While vishing can also be used to impersonate executives, the medium here is email, and the specific term for email-based executive impersonation for fraud is BEC, not vishing.
- ✓
Business email compromise (BEC)
Why this is correct
BEC is a form of phishing where an attacker impersonates a high-level executive or trusted partner to trick employees into transferring funds or revealing sensitive information. The misspelled domain and urgent wire transfer request are classic BEC indicators. The attacker aims to commit fraud by leveraging authority and urgency, which aligns exactly with this scenario.
- ✗
Whaling
Why it's wrong here
Whaling is a type of phishing specifically targeting senior executives, such as the CEO or CFO. In this scenario, the CEO is being impersonated, but the target is an employee, not the executive. Whaling would involve sending a phishing email to the CEO, not from a spoofed CEO to an employee. Therefore, this is not whaling.
Go deeper
Related to this question
Learn chapter
Phishing, Vishing, and Smishing
Key term
Impersonation
Impersonation is a security attack where an attacker pretends to be a legitimate person or system to gain unauthorized access, steal data, or commit fraud.
Key term
Business email compromise
Business email compromise is a sophisticated cyberattack where a criminal impersonates a trusted person or organization via email to trick the victim into transferring money or revealing sensitive information.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.