Courseiva
Malware, Social Engineering and Network AttacksmediumMultiple ChoiceObjective-mapped

CEH Spear Phishing Practice Question

An employee receives an email that appears to be from the company's CEO, requesting an urgent wire transfer to a vendor. The email address is slightly different from the CEO's actual address. Which type of social engineering attack is this?

⚠ Common exam trap

In the EC-CEH exam, candidates often confuse whaling with spear phishing because both are targeted. However, the key distinction is the target's level: whaling targets top executives (C-suite, board members), while spear phishing targets any individual. Here, since the recipient is an employee, it is spear phishing, not whaling.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Spear phishing

Spear phishing is a targeted social engineering attack aimed at a specific individual or organization. In this scenario, the email is personalized to appear from the CEO but targets an employee, making it spear phishing. Unlike whaling, which targets high-profile executives, spear phishing can target any individual. The slightly spoofed email address and urgent request for a wire transfer are common spear phishing tactics, exploiting trust and authority to trick the victim.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing

    Why it's wrong here

    Phishing refers to a broad, non-targeted social engineering attack distributed widely to a large number of recipients, often using generic lures and lacking specific personalization. These attacks typically aim to harvest credentials or spread malware without tailoring the content to individual victims. The described scenario involves an email specifically crafted for a particular employee, making it a targeted attack rather than general, untargeted phishing.

  • Vishing

    Why it's wrong here

    Vishing, or voice phishing, is a social engineering attack conducted exclusively over telephone calls, often leveraging Voice over IP (VoIP) to spoof caller ID. Attackers attempt to trick victims into revealing sensitive information or performing actions by impersonating legitimate entities. Since the described scenario involves an email-based attack, it fundamentally does not align with the definition of vishing.

  • Whaling

    Why it's wrong here

    Whaling is a highly targeted form of spear phishing specifically aimed at senior executives, such as CEOs, CFOs, or other high-value targets within an organization. The objective is to gain access to critical data or authorize significant financial transactions, often involving large sums of money. Although the email in this scenario appears to originate from the CEO, the recipient is a regular employee, not an executive, therefore it is not classified as whaling.

  • Spear phishing

    Why this is correct

    This is spear phishing because the email is crafted specifically for that employee, using the CEO's identity to add urgency and authority. The targeted nature and the spoofed email address are hallmarks of spear phishing.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.