Courseiva
Malware, Social Engineering and Network AttackseasyMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

A security analyst receives an email from what appears to be the company's CEO requesting an urgent wire transfer. The email address is slightly misspelled (e.g., ce0@company.com instead of ceo@company.com). Which type of social engineering attack is this?

⚠ Common exam trap

The trap is confusing whaling with spear phishing. Whaling targets senior executives; this attack targets a security analyst by impersonating the CEO, so it is spear phishing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Spear phishing

Spear phishing is a targeted phishing attack aimed at a specific individual or group. In this scenario, the attacker sends an email impersonating the CEO to a specific security analyst, making it a spear phishing attempt. The target is the analyst, not the CEO, so it is not whaling, which targets senior executives directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vishing

    Why it's wrong here

    Vishing, or voice phishing, is a social engineering attack conducted exclusively over voice communication channels, typically via telephone calls or Voice over IP (VoIP). Unlike email-based attacks, vishing relies on verbal manipulation and urgency to trick victims into divulging confidential information, such as account numbers or passwords. Since the scenario explicitly describes an attack received via 'email,' vishing is an incorrect classification for this specific method of delivery.

  • Phishing

    Why it's wrong here

    Phishing refers to a broad, untargeted social engineering attack that casts a wide net, sending generic malicious emails to a large number of recipients indiscriminately. These attacks typically lack personalization and rely on sheer volume, hoping a small percentage of recipients will fall for common lures like fake login pages or urgent account notifications. In this scenario, the attack is specifically directed at a 'security analyst,' indicating a targeted approach rather than a general, mass-distributed campaign.

  • Whaling

    Why it's wrong here

    Whaling is a highly specialized form of spear phishing that specifically targets high-profile individuals within an organization, such as C-level executives, board members, or other senior management. The objective is often to initiate large financial transfers or gain access to highly sensitive corporate data by impersonating a trusted authority. While the scenario mentions the CEO, they are the *impersonated sender* of the malicious email, not the *target* of the attack, which is the security analyst, making whaling an inappropriate classification.

  • Spear phishing

    Why this is correct

    Spear phishing is a highly targeted form of email-based social engineering where attackers craft personalized messages for a specific individual, such as a security analyst. These emails often leverage specific knowledge about the target, their role, or their organization, making the lure appear highly credible and increasing the likelihood of the recipient falling victim. The goal is typically to trick the individual into revealing sensitive information, clicking a malicious link, or downloading an infected attachment, directly aligning with the scenario described.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.