220-1102 exam dumps

220-1102 practice question 452 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 452

Single answerBusiness email compromise (BEC)

A finance assistant receives an email that appears to come from the company's CEO, who is traveling overseas. The message says a confidential acquisition is in progress and instructs the assistant to urgently change a vendor's bank account information and send payment before the end of the day. The sender display name shows the CEO's name, but the actual email address is from a free webmail domain. The email contains no malware attachment or link. What is the BEST action for the technician to recommend before any payment is processed?

  1. A

    Reply to the email and ask the CEO to confirm the new bank details

  2. B

    Verify the request using a trusted out-of-band method, such as calling the CEO or vendor using known contact information

  3. C

    Open the email headers and, if SPF passes, process the payment as requested

  4. D

    Quarantine the message and delete all emails from the CEO until the trip is over

Show answer and explanation

Correct answer: B

Explanation

This scenario is a classic business email compromise (BEC) attempt: urgency, executive impersonation, secrecy, and a request to change payment instructions. BEC frequently does not involve malicious attachments or links, which is why focusing only on malware indicators can miss the threat. The best practice is to verify any request involving funds transfer, payroll changes, gift cards, or vendor banking updates through an out-of-band method using known-good contact information, not contact details provided in the suspicious message. This approach is consistent with common security awareness guidance from organizations such as the FBI's Internet Crime Complaint Center (IC3), CISA, and NIST security awareness best practices. Technical controls like SPF, DKIM, and DMARC can help identify spoofing, but they do not replace business process controls and independent verification for high-risk financial actions.

  • A. Incorrect.

    This is incorrect because replying to the suspicious email keeps communication within the potentially fraudulent channel controlled by the attacker. In a business email compromise scenario, the attacker may be monitoring or spoofing the conversation and can simply respond with convincing details. A common misconception is that asking for confirmation by email is enough, but BEC specifically exploits trust in email communication.

  • B. Correct.

    This is correct because business email compromise often relies on impersonation and social engineering rather than malware. The safest response is to independently verify the request through a separate, trusted channel, such as calling the executive or vendor using a phone number from an internal directory, ERP system, or prior verified records. This aligns with standard anti-fraud controls for payment changes and urgent financial requests.

  • C. Incorrect.

    This is incorrect because email authentication results like SPF are only one signal and do not prove a payment change request is legitimate. A message can pass technical checks yet still be fraudulent, especially if an attacker uses a lookalike domain or a compromised account. The misconception here is assuming that passing an email validation check is sufficient approval for a financial transaction.

  • D. Incorrect.

    This is incorrect because although quarantining a suspicious message may be appropriate as part of incident handling, deleting all emails from the CEO is excessive and disruptive to business operations. It also does not address the immediate need to validate the payment request safely. The better control is verification of the transaction request through established procedures.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam