nerdexam
EC-Council

312-50V12 · Question #183

An experienced cyber attacker has created a fake LinkedIn profile, successfully impersonating a high-ranking official from a well-established company, to execute a social engineering attack. The…

The correct answer is A. Whaling and Targeted Attacks. The attacker employed whaling by impersonating a high-ranking official to gain unauthorized access and sensitive information, directly enabling further targeted attacks against the organization.

Submitted by mateo_ar· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

An experienced cyber attacker has created a fake LinkedIn profile, successfully impersonating a high-ranking official from a well-established company, to execute a social engineering attack. The attacker then connected with other employees within the organization, receiving invitations to exclusive corporate events and gaining access to proprietary project details shared within the network. What advanced social engineering technique has the attacker primarily used to exploit the system and what is the most likely immediate threat to the organization?

Options

  • AWhaling and Targeted Attacks
  • BPretexting and Network Vulnerability
  • CSpear Phishing and Spam
  • DBaiting and Involuntary Data Leakage

How the community answered

(19 responses)
  • A
    79% (15)
  • B
    5% (1)
  • C
    11% (2)
  • D
    5% (1)

Why each option

The attacker employed whaling by impersonating a high-ranking official to gain unauthorized access and sensitive information, directly enabling further targeted attacks against the organization.

AWhaling and Targeted AttacksCorrect

Whaling is a highly specific form of phishing that targets high-ranking individuals or executives, which precisely matches the attacker's action of impersonating a 'high-ranking official' to gain trust and access. The acquisition of 'proprietary project details' and 'invitations to exclusive corporate events' indicates that the attacker is performing 'Targeted Attacks,' leveraging the initial social engineering success for deeper, specific exploitation against the organization rather than a broad, untargeted approach.

BPretexting and Network Vulnerability

While pretexting involves creating a fabricated scenario, the specific impersonation of a high-ranking official makes 'whaling' a more precise classification for this advanced technique. 'Network Vulnerability' refers to technical flaws in infrastructure, not the social engineering and information access described as the immediate threat.

CSpear Phishing and Spam

Spear phishing targets specific individuals, but whaling is a more refined term that specifically applies when the target or impersonation involves high-ranking officials. 'Spam' refers to unsolicited bulk messages and is not a targeted social engineering technique as described.

DBaiting and Involuntary Data Leakage

Baiting involves luring victims with a tempting offer or physical device, which does not align with the scenario of a fake LinkedIn profile and impersonation. 'Involuntary Data Leakage' implies accidental disclosure, whereas the described scenario involves an attacker actively and maliciously extracting information.

Concept tested: Advanced social engineering techniques and associated threats

Source: https://learn.microsoft.com/en-us/training/modules/describe-social-engineering-techniques/3-social-engineering-techniques

Topics

#whaling#social engineering#impersonation#targeted attack

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice