Courseiva
Malware, Social Engineering and Network AttackshardMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

An attacker uses the Social Engineering Toolkit (SET) to craft a phishing email that appears to come from the company's CEO, requesting the recipient to urgently wire funds to a new vendor. This attack is BEST described as which type of social engineering?

⚠ Common exam trap

The EC-CEH exam often tests the distinction between spear phishing and whaling by making candidates think any targeted email is spear phishing, but the trap here is that whaling is a subset of spear phishing specifically targeting senior executives, so the correct answer is the more specific term when the target is a 'big fish' like the CEO.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Whaling

Whaling is a targeted phishing attack aimed at high-profile individuals like the CEO or CFO. In this scenario, the attacker uses SET to impersonate the CEO and requests an urgent wire transfer, which is a classic whaling tactic because it targets a senior executive (the recipient) with a business-critical request. The attack is not generic phishing but specifically targets a 'big fish' within the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pretexting

    Why it's wrong here

    Pretexting relies on an elaborate, pre-planned scenario or "pretext" to manipulate the target into divulging information or performing an action. This often involves impersonating someone in authority or a trusted entity and engaging in a conversation to build rapport and trust over time. The scenario described, however, appears to be a more direct impersonation for a specific action rather than an unfolding, fabricated narrative designed to extract information through a detailed backstory.

  • Spear phishing

    Why it's wrong here

    Spear phishing is a highly targeted form of phishing that focuses on specific individuals or organizations, often leveraging personalized information to increase credibility and trick the victim. While the attack described is indeed targeted, the critical distinguishing factor here is the elevated status of the intended victim, which is a senior executive or high-value target. Spear phishing can target anyone with personalized information, whereas whaling specifically targets the upper echelons of an organization.

  • Whaling

    Why this is correct

    Whaling is a specialized form of phishing attack specifically designed to target high-ranking individuals within an organization, such as CEOs, CFOs, or other senior executives. These attacks are often highly sophisticated, leveraging extensive research to craft convincing lures that exploit the target's position of authority and access to sensitive information or financial assets. The scenario involving the impersonation of a CEO directly aligns with the definition of whaling, as it targets a "big fish" with significant organizational power.

  • Quid pro quo

    Why it's wrong here

    Quid pro quo social engineering involves an attacker offering a perceived benefit or service in exchange for information or access from the target. This often manifests as a "help desk" call offering to fix a problem in exchange for login credentials, or a survey offering a prize for participation. The described attack, however, is a direct impersonation aimed at eliciting a specific action or information without offering any reciprocal service or benefit to the victim.

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.