Courseiva
Malware, Social Engineering and Network AttacksmediumMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

An organization receives an email that appears to be from the CEO, urgently requesting that the recipient wire funds to a new vendor. The email contains the CEO's name and title but the sender address is slightly misspelled. Which type of social engineering attack is this?

⚠ Common exam trap

Test-takers frequently choose 'Spear phishing' because they recognize it as a targeted email attack, but fail to distinguish that 'Whaling' is the specific subtype reserved for high-level executives, which is the key differentiator in CEH exam questions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Whaling

This is a whaling attack because the attacker impersonates a high-profile executive (the CEO) to deceive the recipient into transferring funds. Whaling is a subtype of spear phishing that specifically targets individuals with authority or financial access, often by spoofing a senior executive's email address. In this scenario, the CEO's identity is used to exploit trust and urgency, making it a whaling attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pretexting

    Why it's wrong here

    Pretexting is a social engineering technique where an attacker creates a fabricated scenario, or 'pretext,' to manipulate a target into divulging information or performing an action. This deception relies on building a believable false narrative, often involving impersonation or a sense of urgency, to gain trust. While it can be delivered via email, its defining characteristic is the elaborate story rather than the specific communication channel. The question's focus on an email *from* an organization points to the delivery of a specific type of attack, not the underlying fabrication method itself.

  • Whaling

    Why this is correct

    Whaling is a highly targeted form of phishing specifically aimed at senior executives, C-level management, or other high-profile individuals within an organization. These attacks are meticulously crafted and personalized, often leveraging publicly available information to create convincing emails that appear to come from a legitimate, trusted source, such as a legal firm or a high-ranking internal contact. The objective is typically to trick the executive into authorizing large wire transfers, revealing sensitive corporate data, or granting access to critical systems. The scenario describes an email likely targeting a high-level individual, making whaling the most precise classification.

  • Vishing

    Why it's wrong here

    Vishing, a portmanteau of 'voice' and 'phishing,' is a social engineering attack conducted over telephone calls or Voice over IP (VoIP) systems. Attackers use deceptive voice messages or live conversations to trick individuals into revealing personal information, financial details, or performing actions like installing malware. Since the question explicitly states the attack vector is an 'email,' vishing is immediately ruled out as its defining characteristic is the use of voice communication.

  • Spear phishing

    Why it's wrong here

    Spear phishing is a sophisticated phishing attack that targets specific individuals or groups within an organization with personalized and relevant emails. Unlike general phishing, these emails are not mass-distributed but are tailored to the recipient, often containing specific details to increase their legitimacy and bypass standard security filters. While whaling is a *type* of spear phishing, the term 'whaling' specifically denotes attacks against high-value targets like senior executives, making it a more precise classification when the target's executive status is implied by the email's apparent origin or intent. The question's context suggests a high-level target, making whaling a more accurate fit.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.