Courseiva
Security Operations →easyMultiple Choice

ISC2 CC Security Operations Practice Question

A new employee reports receiving an email that appears to come from the CEO, urgently requesting gift card purchases for a client. The email domain looks almost identical to the company's domain but uses a different top-level domain. Which type of social engineering attack is this?

⚠ Common exam trap

The trap here is labeling any targeted email as spear phishing and overlooking the executive impersonation and look-alike domain that specifically define business email compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business email compromise (BEC) using a look-alike domain

The message impersonates an executive, uses a domain that closely resembles the real one, and pressures the recipient into an urgent financial action. That combination is the hallmark of business email compromise, specifically using a look-alike domain. Spear phishing, watering hole, and vishing describe different delivery methods or objectives and do not capture the executive impersonation and fraudulent payment request.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Business email compromise (BEC) using a look-alike domain

    Why this is correct

    The scenario describes an attacker impersonating an executive and using a deceptively similar domain to pressure the recipient into an unauthorized financial action. This matches business email compromise, which often relies on spoofed or look-alike domains and urgency to bypass scrutiny. The gift card request is a classic BEC cash-out method rather than a technical exploitation technique.

  • ✗

    Vishing using caller ID spoofing

    Why it's wrong here

    Vishing is voice-based social engineering conducted over the phone, often with spoofed caller ID. Here the initial contact is an email, and the deceptive element is the look-alike domain. No phone call or voice interaction is described, so vishing does not fit.

  • ✗

    Watering hole attack

    Why it's wrong here

    A watering hole attack compromises a website the target group is known to visit, then serves malware from that site. This scenario involves a direct email message with a fraudulent request and no compromised website. The delivery method and objective do not match a watering hole.

  • ✗

    Spear phishing with a malicious attachment

    Why it's wrong here

    Spear phishing is targeted, but the defining element in this scenario is the impersonation of an executive and the fraudulent financial request, not an attachment. No malware payload or credential harvesting link is described. Classifying it only as spear phishing misses the business email compromise pattern and the look-alike domain indicator.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.