ISC2 CC Security Operations Practice Question
A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?
⚠ Common exam trap
The trap here is labeling any targeted email as spear phishing and overlooking the executive impersonation and look-alike domain that specifically define business email compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business email compromise (BEC) using a look-alike domain
The message impersonates an executive, uses a domain that closely resembles the real one, and pressures the recipient into an urgent financial action. That combination is the hallmark of business email compromise, specifically using a look-alike domain. Spear phishing, watering hole, and vishing describe different delivery methods or objectives and do not capture the executive impersonation and fraudulent payment request.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Business email compromise (BEC) using a look-alike domain
Why this is correct
The scenario describes an attacker impersonating an executive and using a deceptively similar domain to pressure the recipient into an unauthorized financial action. This matches business email compromise, which often relies on spoofed or look-alike domains and urgency to bypass scrutiny. The gift card request is a classic BEC cash-out method rather than a technical exploitation technique.
- ✗
Vishing using caller ID spoofing
Why it's wrong here
Vishing is voice-based social engineering conducted over the phone, often with spoofed caller ID. Here the initial contact is an email, and the deceptive element is the look-alike domain. No phone call or voice interaction is described, so vishing does not fit.
- ✗
Watering hole attack
Why it's wrong here
A watering hole attack compromises a website the target group is known to visit, then serves malware from that site. This scenario involves a direct email message with a fraudulent request and no compromised website. The delivery method and objective do not match a watering hole.
- ✗
Spear phishing with a malicious attachment
Why it's wrong here
Spear phishing is targeted, but the defining element in this scenario is the impersonation of an executive and the fraudulent financial request, not an attachment. No malware payload or credential harvesting link is described. Classifying it only as spear phishing misses the business email compromise pattern and the look-alike domain indicator.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Impersonation
Impersonation is a security attack where an attacker pretends to be a legitimate person or system to gain unauthorized access, steal data, or commit fraud.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.