CEH Spear phishing Practice Question
A penetration tester receives an email that appears to be from the company's CEO, urgently requesting that the tester click a link to review a document. The email contains several grammatical errors and the sender's address is slightly misspelled. Which type of social engineering attack is this MOST likely?
⚠ Common exam trap
In EC-CEH, whaling specifically targets C-level executives as victims, whereas spear phishing targets any specific individual. Candidates often mistake the impersonation of a CEO as whaling, but the key is who the recipient is. Since the recipient is a penetration tester (not a senior executive), this is spear phishing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spear phishing
This attack is spear phishing because the email is targeted at a specific individual (the penetration tester) and impersonates a trusted source (the CEO) to trick the recipient into clicking a malicious link. While whaling targets high-level executives, spear phishing targets any specific person, and here the recipient is not a senior executive. The grammatical errors and misspelled sender address are common indicators of phishing, but the targeted nature distinguishes it from generic phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Whaling
Why it's wrong here
Whaling is a highly sophisticated form of spear phishing that specifically targets senior executives or high-profile individuals within an organization, often aiming for significant financial gain or access to critical corporate data. The defining characteristic is the victim's organizational status and the high-value nature of the target. In this scenario, while the email impersonates a CEO, the *target* is a penetration tester, who typically does not hold the executive-level position that defines a whaling attack, making this classification incorrect.
- ✗
Baiting
Why it's wrong here
Baiting is a social engineering technique where an attacker offers a tempting lure, such as a "free" download, a physical infected USB drive left in a public place, or a promise of exclusive content, to entice a victim into taking a specific action that compromises their security. The primary mechanism is the promise of a desirable item or service in exchange for a risky action. The scenario describes an email with a link request, lacking any explicit "bait" or enticing offer beyond the implied authority of the CEO, which distinguishes it from a baiting attack.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a social engineering attack that exclusively utilizes voice communication channels, such as telephone calls or voicemail messages, to trick individuals into divulging sensitive information or performing actions. The core medium of interaction is auditory, relying on verbal manipulation and often urgency. Since the attack described in the question stem is explicitly delivered via an email, it does not involve voice communication and therefore cannot be classified as vishing.
- ✓
Spear phishing
Why this is correct
Spear phishing involves crafting highly personalized email attacks directed at a specific individual, group, or role within an organization, leveraging known information about the target to increase credibility. The attacker often impersonates a trusted entity, such as a CEO, to manipulate the recipient into performing a desired action, like clicking a malicious link. In this case, the email is specifically tailored and sent to a penetration tester, impersonating the CEO, which precisely fits the definition of a spear phishing attempt due to its targeted nature and social engineering tactics.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.