What Type of Attack is a Suspicious Email from the CEO?
During a security awareness training session, an employee reports receiving an email that appears to be from the CEO requesting an urgent wire transfer. The email has a suspicious domain and poor grammar. Which type of attack is this an example of?
Quick Answer
Phishing is the correct classification because the scenario has every hallmark of the category: a deceptive email impersonating a trusted figure, the CEO, designed to manipulate the recipient into taking a specific, damaging action, an urgent wire transfer, delivered through a suspicious domain and marked by poor grammar that betrays its illegitimacy on closer inspection. Phishing is fundamentally a social engineering technique; it succeeds not by breaking technical defenses but by exploiting trust, urgency, and authority to get a human being to act against their own or their organization's interest. The impersonation of a senior executive combined with a request for urgent financial action is a very common phishing pattern precisely because it pressures the recipient to act quickly, before they have time to verify the request through a separate channel like a phone call. What keeps this a general phishing example rather than a more targeted variant is the description itself: the email isn't described as being crafted specifically around details unique to this employee or tailored convincingly to the CEO's actual writing style, it's a broad, somewhat clumsy attempt, evident from the suspicious domain and poor grammar, rather than a carefully researched, individually customized message. When a question describes a deceptive email impersonating an authority figure to induce a risky action, and doesn't emphasize deep personalization or research into the target, phishing is the category to recognize, distinguished from more narrowly targeted social engineering variants by that lack of tailored specificity.
⚠ Common exam trap
Test-takers frequently confuse the broad category of phishing with its subtypes: candidates often pick 'spear phishing' or 'whaling' because the email targets a specific role (CEO), but the lack of personalization and generic red flags make it a standard phishing attack, not a targeted one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing
This is a classic example of phishing, a broad category of social engineering attacks where attackers send deceptive emails to trick recipients into revealing sensitive information or performing actions like wire transfers. The email's suspicious domain and poor grammar are telltale signs of a generic phishing attempt, as it is not specifically tailored to the employee or the CEO's identity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Smishing
Why it's wrong here
Smishing uses SMS messages, not email.
- ✓
Phishing
Why this is correct
The email is a classic phishing attempt: it impersonates a trusted entity (CEO) and requests sensitive action (wire transfer).
- ✗
Spear phishing
Why it's wrong here
Spear phishing is a targeted form of phishing aimed at a specific individual or organization, but in this scenario the email is generic and not necessarily targeted.
- ✗
Whaling
Why it's wrong here
Whaling targets high-profile executives, but the email is from the CEO, not targeting the CEO.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security awareness training program is being developed. Which topic is most important to include to reduce the risk of credential theft?
easy- A.Proper use of social media
- B.Physical security procedures
- ✓ C.Recognizing phishing attempts
- D.Data backup procedures
Why C: Phishing is the primary vector for credential theft, as attackers use deceptive emails or messages to trick users into revealing usernames and passwords. Training users to recognize phishing attempts—such as spoofed sender addresses, suspicious URLs, and urgent language—directly mitigates this risk by preventing credential disclosure at the point of attack. Unlike other topics, phishing awareness specifically targets the social engineering techniques most commonly used to steal credentials.
Variation 2. Which THREE of the following are examples of security awareness training topics?
easy- A.How to apply patches to servers
- ✓ B.Recognizing phishing emails
- C.Configuring firewall rules
- ✓ D.Physical security best practices (e.g., locking screens)
- ✓ E.Social engineering tactics
Why B: Recognizing phishing emails is a core security awareness training topic that teaches users to identify social engineering attempts, such as spoofed sender addresses, suspicious links, and urgent language. This training reduces the risk of credential theft and malware installation, which are common attack vectors in organizations.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.