📖 What is Spear Phishing?

Spear Phishing is a targeted form of phishing where an attacker sends a personalized message to a specific individual or small group. By using gathered intelligence about the target, the attacker increases the likelihood that the victim will trust the message and reveal sensitive data.

🥋 Sensei Says:

"Contrast this with "phishing" (broad/generic). If the attacker knows the target's name or job title, it's "spear" phishing."

📚 Certification: CompTIA Security+ Certification Exam (SY0-701)

🔑 What are the Key Concepts of Spear Phishing?

  • Attackers perform reconnaissance using OSINT, gathering data from social media and company websites to make the message appear authentic and trustworthy.
  • Personalization is the defining characteristic, utilizing specific names, job titles, or internal project details to bypass the victim's natural suspicion.
  • These attacks leverage social engineering tactics, such as urgency or authority, tailored specifically to the victim's professional role or personal interests.
  • The primary goal is often credential theft or malware delivery, using highly convincing lures like targeted invoices or internal company memos.

🎯 How does Spear Phishing appear on the SY0-701 Exam?

A scenario might describe an HR manager receiving an email that references a specific employee's name and a recent internal policy change. You will be asked to identify this as spear phishing.

You may be asked to distinguish between a generic phishing campaign sent to thousands of users and a targeted attack aimed at the accounting department to steal financial data.

Expect questions where you must identify the reconnaissance phase of an attack, specifically when an attacker uses LinkedIn to find the names of IT administrators to craft a convincing lure.

❓ Frequently Asked Questions

What is the difference between spear phishing and whaling?

While both are targeted, spear phishing can target any specific individual or group. Whaling is a specialized subset of spear phishing that exclusively targets high-profile executives, such as the CEO or CFO.


Can spear phishing be conducted through channels other than email?

Yes. While email is most common, spear phishing can occur via SMS (smishing) or voice calls (vishing), provided the attacker uses personalized information to target a specific individual.

Related Terms from CompTIA Security+ Certification Exam

📝 Related Study Guides

Study Guide 9 min read

How to Pass CompTIA Security+ (SY0-701) on Your First Try

To pass CompTIA Security+ SY0-701 on your first try, build a structured 6-8 week study plan covering all five domains, prioritize understanding concepts over memorization, practice with scenario-based questions daily, and consistently score 85% or higher on practice exams before scheduling your test. Hands-on lab experience is essential for performance-based questions.

Deep Dive 8 min read

Zero Trust Architecture: Security+ (SY0-701) Deep Dive

Zero Trust architecture is a security framework based on the principle "never trust, always verify." Unlike traditional perimeter security, it assumes breaches are inevitable and requires strict identity verification for every person and device attempting to access resources, regardless of whether they are inside or outside the network perimeter.

Exam Tips 8 min read

Security+ PBQs: Master Firewall ACLs & Incident Response

Security+ Performance-Based Questions (PBQs) are scenario-driven simulations requiring you to apply knowledge to real-world tasks. To master them, focus on firewall ACL rule ordering, the "implicit deny" principle, and analyzing system logs for incident response. Consistent practice with high-fidelity simulations is the most effective way to ensure exam success.

🧠

Test Your Knowledge

Think you understand Spear Phishing? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium