Courseiva
mediumMatchingObjective-mapped

CISSP Match each threat type to its description. Practice Question

Match each threat type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Fraudulent emails to obtain sensitive info

Targeted phishing at specific individuals

Phishing targeting senior executives

Voice phishing over phone

Phishing via SMS

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Phishing: Mass email sent to many users to trick them into revealing personal information.

The correct matches are: Phishing with mass email (A), Spear Phishing with targeted attacks (C), and Whaling with executive targets (D). Option B is incorrect because it describes spear phishing, not phishing. Option E is also incorrect as it misassigns whaling as mass email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Phishing: Mass email sent to many users to trick them into revealing personal information.

    Why this is correct

    This option correctly defines general phishing as a widespread social engineering technique involving the distribution of mass emails to numerous users, often impersonating a legitimate entity like a bank or popular service. The primary goal is to deceive recipients into clicking malicious links or divulging sensitive personal information, such as login credentials or financial details, through a sense of urgency or fear, without specific individual targeting.

  • Phishing: Targeted attack on a specific individual

    Why it's wrong here

    This statement incorrectly defines general phishing, which is characterized by its broad, untargeted distribution to a large number of recipients, rather than focusing on a single individual. A targeted attack on a specific individual is precisely the definition of spear phishing, where the attacker invests time in reconnaissance to personalize the lure, making this option an inaccurate description of standard phishing.

  • Spear Phishing: Targeted phishing attack aimed at a specific individual or organization.

    Why this is correct

    Spear phishing is accurately described as a highly targeted form of phishing, where attackers meticulously research a specific individual or organization to craft a personalized and convincing fraudulent communication. This tailored approach significantly increases the likelihood of success compared to generic phishing campaigns, as the victim is more likely to trust the seemingly legitimate sender or context due to the personalized details.

  • Whaling: Phishing attack targeting high-profile employees like executives.

    Why this is correct

    Whaling correctly identifies a specialized phishing attack specifically aimed at high-value targets within an organization, such as C-level executives, senior management, or other influential personnel. These attacks are often highly sophisticated, leveraging detailed knowledge of the target's role and company operations to trick them into authorizing significant financial transfers or divulging critical corporate secrets, due to their authority and access.

  • Whaling: Mass email sent to many users

    Why it's wrong here

    This statement is incorrect because whaling, by its very nature, is a highly targeted attack, not a mass email campaign. Whaling specifically focuses on a very small number of high-profile individuals, such as executives, using meticulously crafted and personalized messages. This stands in direct contrast to the broad, untargeted distribution characteristic of mass emails, which is typical of general phishing, not whaling.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.