200-201 Question 137
Select 3An e-commerce company has detected unauthorized transactions in their payment system. As part of your cybersecurity operations role, you are tasked with analyzing transaction data to identify suspicious activity. Which of the following pieces of transaction data would be the most relevant to flag potential fraudulent behavior?
- A
Unusual transaction amounts compared to the user’s typical spending pattern
- B
The user's account password last modification date
- C
Geographical location of the transaction being inconsistent with the user's usual location
- D
Time of the transaction falling outside the user's typical activity hours
- E
The IP address used for the transaction matching the user's previously recorded IP addresses
Show answer and explanation
Correct answers: A, C, D
Explanation
When analyzing transaction data for potential fraud, it is critical to focus on anomalies such as unusual transaction amounts, geographical discrepancies, and deviations from normal activity times. These indicators suggest unauthorized access or misuse of the account. While factors such as password modification dates or matching IP addresses may provide context, they are less directly relevant to identifying fraudulent transactions.
- A. Correct.
Unusual transaction amounts are a strong indicator of fraudulent activity, especially if they deviate significantly from the user’s historical spending pattern.
- B. Incorrect.
The account password modification date is not directly related to the transaction itself and is less relevant for identifying fraudulent transactions.
- C. Correct.
Geographical location inconsistency can indicate unauthorized access or fraudulent activity, especially when the location is drastically different from the user's usual area.
- D. Correct.
Transactions occurring outside the user's normal activity hours can be a red flag for fraudulent activity, as it deviates from their typical behavioral patterns.
- E. Incorrect.
Matching IP addresses with the user's historical IP data would generally suggest normal activity, rather than fraudulent behavior, making it less useful for flagging potential fraud.