Courseiva
Malware, Social Engineering and Network AttacksmediumMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

An employee receives an email that appears to be from the CEO, requesting an urgent wire transfer. The email address is slightly misspelled (e.g., ceo@cornpany.com instead of ceo@company.com). This is an example of which type of attack?

⚠ Common exam trap

Many candidates confuse 'whaling' with 'spear phishing' because both target specific individuals, but whaling specifically targets high-level executives, while spear phishing can target any individual within an organization, as in this case where the email impersonates the CEO rather than targeting them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Spear phishing

Spear phishing is a targeted phishing attack aimed at a specific individual or organization, using personalized information to increase credibility. In this scenario, the attacker spoofs the CEO's identity and uses a misspelled domain (typosquatting) to trick the employee into performing a wire transfer, which is a classic spear phishing technique. Unlike generic phishing, spear phishing tailors the message to the victim's role and context, making it more effective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Whaling

    Why it's wrong here

    Whaling is a highly specific form of spear phishing that exclusively targets high-profile individuals within an organization, such as C-level executives (CEO, CFO, CTO) or senior government officials. These attacks are meticulously crafted, often leveraging extensive reconnaissance to impersonate authoritative figures or critical business communications, aiming for significant financial fraud or access to highly sensitive corporate data. The question describes an attack on "an employee," which is too general to classify as whaling without specifying a C-suite or equivalent high-value target.

  • Phishing

    Why it's wrong here

    Phishing refers to a broad, non-targeted social engineering attack typically distributed en masse via email or other electronic communication channels. These campaigns rely on generic lures, such as fake bank alerts or lottery winnings, sent to a wide, indiscriminate audience, hoping a small percentage will fall victim. The attack described, where an email "appears to be from the CEO" to a specific employee, indicates a level of targeting and personalization that distinguishes it from the indiscriminate nature of traditional, generic phishing.

  • Pretexting

    Why it's wrong here

    Pretexting is a social engineering technique where an attacker creates a fabricated scenario or "pretext" to manipulate a victim into divulging sensitive information or performing an action. This often involves impersonating someone in authority or a trusted entity and constructing a believable backstory to build rapport and trust. While the email might involve impersonation, the core of pretexting is the elaborate narrative used to trick the victim, which is not explicitly detailed in the question's description of a direct request from the CEO.

  • Spear phishing

    Why this is correct

    Spear phishing is a highly targeted form of phishing that uses personalized information to increase the credibility and effectiveness of the attack. Attackers conduct reconnaissance to gather details about the target, such as their name, job title, company, and even internal relationships, to craft a convincing email. An email appearing to be from the CEO to a specific employee leverages this personalized context and perceived authority, making it a classic example of a spear phishing attempt designed to elicit a specific response.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.