Spear Phishing vs Whaling: Key Differences
A security analyst receives an email that appears to be from the CEO, urgently requesting a wire transfer. The email address is slightly misspelled (ceo@cornpany.com instead of ceo@company.com). Which type of social engineering attack is this?
Quick Answer
The answer is spear phishing. This is correct because the attack is highly targeted at a specific individual—the security analyst—using a spoofed domain and a personalized pretext that mimics the CEO’s identity, which are hallmarks of spear phishing rather than generic phishing or whaling. In whaling, the target is a high-level executive like the CEO themselves, not an employee being impersonated; here, the analyst is the recipient, making it a classic spear phishing scenario. On the Certified Ethical Hacker CEH exam, this distinction tests your understanding of social engineering variants, often appearing in scenario-based questions where the key is identifying who is being targeted versus who is being impersonated. A common trap is confusing whaling with spear phishing when a C-level title appears, but remember: whaling hooks the whale, spear phishing targets the specific fish. Memory tip: “Spear” is precise and personal; “whale” is the big catch, not the bait.
⚠ Common exam trap
The EC-CEH exam often tests the distinction between generic phishing and spear phishing by including a personalized element (like a specific name or role) to trick candidates into choosing the broader 'Phishing' option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spear phishing
Spear phishing is a targeted social engineering attack where the attacker customizes the message for a specific individual or organization, often using a spoofed or lookalike domain. In this scenario, the email is directed at a security analyst, impersonates the CEO, and uses a slightly misspelled domain (ceo@cornpany.com) to deceive the recipient, which is a classic spear phishing technique because it targets a specific role within the company.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vishing
Why it's wrong here
Vishing is voice phishing, not email.
- ✗
Whaling
Why it's wrong here
Whaling targets high-profile executives, but here the target is the analyst.
- ✓
Spear phishing
Why this is correct
Targeted at a specific individual with personalized content.
- ✗
Phishing
Why it's wrong here
Phishing is a broader, non-targeted attack; this is targeted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst receives an email from what appears to be the company's CEO requesting an urgent wire transfer. The email address is slightly misspelled (e.g., ce0@company.com instead of ceo@company.com). Which type of social engineering attack is this?
easy- A.Vishing
- B.Phishing
- C.Whaling
- ✓ D.Spear phishing
Why D: Spear phishing is a targeted phishing attack aimed at a specific individual or group. In this scenario, the attacker sends an email impersonating the CEO to a specific security analyst, making it a spear phishing attempt. The target is the analyst, not the CEO, so it is not whaling, which targets senior executives directly.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.