220-1102 Question 435
Single answerWhalingA company's CFO receives an email that appears to come from the CEO while the CEO is traveling. The message is marked urgent and asks the CFO to purchase several high-value gift cards immediately and send the card numbers back by email for a confidential client event. The sender name matches the CEO, but the reply-to address uses an external domain that differs slightly from the company's real domain. Which type of attack is this, and what is the BEST immediate response by the CFO?
- A
Whaling; verify the request through a known trusted channel such as calling the CEO's listed number before taking any action
- B
Vishing; reply to the email and ask for additional justification before purchasing anything
- C
Spear phishing; forward the email to all employees as a warning and then complete the request if the CEO confirms by email
- D
Pharming; click the sender details and embedded links to confirm whether the company branding looks legitimate
Show answer and explanation
Correct answer: A
Explanation
This scenario describes a classic whaling attack, which is a form of phishing that targets senior executives or employees with financial authority. In practice, this often overlaps with business email compromise (BEC), where attackers impersonate executives and use urgency, secrecy, and authority to pressure victims into sending money, purchasing gift cards, or disclosing sensitive information. The key indicators here are executive impersonation, an urgent financial request, and a look-alike external domain.
The best practice is to stop and verify the request using an out-of-band method, such as calling a known phone number, using an internally published contact method, or following documented approval workflows. Security awareness training from organizations such as CISA and guidance commonly used across the industry emphasize verifying unusual requests, especially those involving funds, gift cards, or confidential transactions, through trusted channels rather than replying to the suspicious message. For A+ Core 2, candidates should recognize whaling as a targeted social engineering attack against high-profile personnel and know that independent verification is the correct immediate response.
- A. Correct.
Correct. Whaling is a targeted phishing attack aimed at high-profile individuals such as executives or finance staff, often involving urgent requests for money, gift cards, wire transfers, or sensitive data. In this scenario, the attacker is impersonating the CEO to pressure the CFO into bypassing normal procedures. The best immediate response is to verify the request through an independent, trusted channel already on file, such as calling the CEO's known phone number or confirming through established internal procedures. This aligns with common security awareness guidance and business email compromise prevention practices.
- B. Incorrect.
Incorrect. Vishing is voice phishing conducted over phone calls or voicemail, not email. Although asking questions may seem cautious, replying to the suspicious email continues engagement with the attacker and does not independently verify the request. A proper response is out-of-band verification using trusted contact information.
- C. Incorrect.
Incorrect. While the message is targeted like spear phishing, the more specific and best classification here is whaling because it involves executive impersonation and a finance executive target in a high-value fraud attempt. Forwarding the message broadly could spread confusion, and relying on email confirmation alone is unsafe because the attacker may control the spoofed or look-alike address. The request should not be completed based on email-only confirmation.
- D. Incorrect.
Incorrect. Pharming involves redirecting users to fraudulent websites, typically through DNS poisoning or host file manipulation, rather than impersonation through a direct executive email request. Clicking links or interacting further with suspicious content increases risk. Visual branding is not a reliable indicator of legitimacy.