CEH Spear Phishing Practice Question
An employee receives an email that appears to be from the company's CEO, requesting an urgent wire transfer to a vendor. The email address is slightly different from the CEO's actual address. Which type of social engineering attack is this?
⚠ Common exam trap
In the EC-CEH exam, candidates often confuse whaling with spear phishing because both are targeted. However, the key distinction is the target's level: whaling targets top executives (C-suite, board members), while spear phishing targets any individual. Here, since the recipient is an employee, it is spear phishing, not whaling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spear phishing
Spear phishing is a targeted social engineering attack aimed at a specific individual or organization. In this scenario, the email is personalized to appear from the CEO but targets an employee, making it spear phishing. Unlike whaling, which targets high-profile executives, spear phishing can target any individual. The slightly spoofed email address and urgent request for a wire transfer are common spear phishing tactics, exploiting trust and authority to trick the victim.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing
Why it's wrong here
Phishing refers to a broad, non-targeted social engineering attack distributed widely to a large number of recipients, often using generic lures and lacking specific personalization. These attacks typically aim to harvest credentials or spread malware without tailoring the content to individual victims. The described scenario involves an email specifically crafted for a particular employee, making it a targeted attack rather than general, untargeted phishing.
- ✗
Vishing
Why it's wrong here
Vishing, or voice phishing, is a social engineering attack conducted exclusively over telephone calls, often leveraging Voice over IP (VoIP) to spoof caller ID. Attackers attempt to trick victims into revealing sensitive information or performing actions by impersonating legitimate entities. Since the described scenario involves an email-based attack, it fundamentally does not align with the definition of vishing.
- ✗
Whaling
Why it's wrong here
Whaling is a highly targeted form of spear phishing specifically aimed at senior executives, such as CEOs, CFOs, or other high-value targets within an organization. The objective is to gain access to critical data or authorize significant financial transactions, often involving large sums of money. Although the email in this scenario appears to originate from the CEO, the recipient is a regular employee, not an executive, therefore it is not classified as whaling.
- ✓
Spear phishing
Why this is correct
This is spear phishing because the email is crafted specifically for that employee, using the CEO's identity to add urgency and authority. The targeted nature and the spoofed email address are hallmarks of spear phishing.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.