220-1102 Question 434
Single answerSpear phishingA company executive reports receiving an email that appears to come from the CFO and asks for an immediate wire transfer to a new vendor. The message uses the CFO's correct name, job title, and writing style, and it references a real project the executive is working on. However, the sender's email address is from a public webmail domain rather than the company's domain. The executive asks the help desk whether this is likely a phishing attempt. Which type of attack is this MOST likely to be?
- A
Whaling
- B
Spear phishing
- C
Vishing
- D
Shoulder surfing
Show answer and explanation
Correct answer: B
Explanation
The best answer is spear phishing because the attacker has used specific personal and organizational information to make the message appear legitimate and to manipulate the target into taking action. In A+ Core 2, candidates are expected to distinguish between general phishing and more targeted attacks such as spear phishing. Whaling is often considered a specialized form of spear phishing directed at executives, but when the question asks for the attack type most clearly demonstrated by the personalized email characteristics, spear phishing is the most accurate answer. Best practices from security awareness guidance, including recommendations commonly aligned with NIST and CISA, include verifying unusual financial requests through a separate trusted channel, checking the sender domain carefully, and treating urgent requests for money or credentials as suspicious.
- A. Incorrect.
Whaling is a targeted phishing attack aimed specifically at high-profile individuals such as executives or other senior leaders. Although this scenario involves executives, the key detail being tested is the personalized, targeted nature of the fraudulent email. A candidate might choose this because the victim and impersonated sender are executives, but the broader and best answer here is spear phishing.
- B. Correct.
Spear phishing is correct because the email is carefully tailored to a specific target, uses real organizational details, impersonates a trusted person, and attempts to trigger urgent financial action. This is a classic example of a targeted phishing message rather than a generic mass phishing campaign.
- C. Incorrect.
Vishing is phishing conducted by voice, typically over a phone call or voicemail. A candidate might choose this if focusing on social engineering in general, but the scenario clearly describes an email-based attack, not a phone-based one.
- D. Incorrect.
Shoulder surfing involves physically observing someone to obtain sensitive information, such as passwords or account data. This option is unrelated to the email-based impersonation and urgency tactics described in the scenario.