Courseiva

CEH Social Engineering and Physical Security Practice Question

A security analyst is reviewing logs from a recent social engineering engagement. The attacker used a phishing email that appeared to come from the company's CEO, requesting that the recipient update their payroll direct deposit information via a link. The link led to a credential harvesting page. Which type of social engineering attack is this?

⚠ Common exam trap

The trap here is selecting the broad category of phishing instead of the more specific business email compromise, which is defined by executive impersonation and financial fraud requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business email compromise (BEC)

Business email compromise (BEC) is a specific type of phishing that involves impersonating a senior executive to manipulate employees into performing financial transactions or disclosing sensitive data. The scenario describes an email spoofing the CEO and requesting a payroll change, which is a classic BEC attack. While it is a form of phishing, the impersonation of an executive and the financial nature of the request distinguish it as BEC. Other options like whaling or vishing do not fit the described attack vector.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Business email compromise (BEC)

    Why this is correct

    Business email compromise (BEC) is a sophisticated scam where an attacker impersonates a high-level executive to trick employees into transferring funds or revealing sensitive information. In this case, the attacker spoofed the CEO's email to request payroll direct deposit changes. BEC often targets employees in finance, HR, or payroll who have the authority to act on such requests. The use of a credential harvesting link is a common BEC tactic to steal login credentials.

  • ✗

    Whaling

    Why it's wrong here

    Whaling is a phishing attack specifically targeting high-level executives, such as CEOs or CFOs. In this scenario, the email is spoofed to appear from the CEO but is sent to a broader group of employees, likely in payroll or HR. The target is not the executive themselves, but rather employees who might act on the CEO's request. Therefore, this is not whaling, which would involve targeting the executive directly.

  • ✗

    Vishing

    Why it's wrong here

    Vishing is voice phishing conducted over the phone. This scenario involves an email with a link, not a phone call. While the attacker might use voice follow-up, the initial attack vector is email. Vishing typically involves a live person or automated voice message attempting to extract information. The described attack does not include any voice component, so it is not vishing.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a broad term for fraudulent emails that attempt to trick recipients into revealing sensitive information. While this attack is a form of phishing, the specific technique of impersonating a CEO to target employees is more precisely termed business email compromise (BEC). Phishing is the general category, but the question asks for the specific type, and BEC is the more accurate answer given the CEO impersonation and the request for financial action.

About these practice questions

Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.