SY0-701 exam dumps

SY0-701 practice question 65 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 65

Single answerVoice call

An accounts payable clerk receives a voice call from someone claiming to be the company's CFO, who says they are traveling and need an urgent wire transfer sent within the hour. The caller ID displays the CFO's name and office number. The caller pressures the clerk not to contact anyone else because the acquisition is confidential. Which of the following is the BEST response to reduce the risk of fraud while still supporting business operations?

  1. A

    Process the transfer because the caller ID matches the CFO's number and the request sounds legitimate

  2. B

    Ask the caller to verify the CFO's employee ID and department before sending the wire

  3. C

    End the call and use a pre-established out-of-band verification method, such as calling the CFO's known number from the corporate directory or confirming through an approved financial authorization process

  4. D

    Reply by email to the CFO's corporate account asking for written confirmation, then process the request immediately if no bounce-back occurs

Show answer and explanation

Correct answer: C

Explanation

This scenario describes vishing, a voice-based social engineering attack. The strongest response is to avoid trusting caller ID or pressure tactics and instead validate the request through a known-good, independent channel and established financial controls. In practice, organizations mitigate these attacks with callback procedures, dual authorization for wire transfers, separation of duties, and documented approval workflows. Security awareness guidance from organizations such as CISA and NIST emphasizes verifying unusual or urgent requests through trusted channels rather than relying on caller ID, email appearance, or information the caller can easily know. The key applied lesson is that voice calls can be weaponized just like phishing emails, so high-risk requests require robust identity verification and process-based controls.

  • A. Incorrect.

    This is incorrect because caller ID can be spoofed, which is a common tactic in vishing and business email compromise-related fraud. Matching caller ID does not provide strong authentication, especially for high-risk financial transactions. The urgency and secrecy are classic social engineering indicators.

  • B. Incorrect.

    This is incorrect because employee IDs, departments, and similar internal details are often discoverable or obtainable through prior reconnaissance, phishing, or insider knowledge. Asking for basic identifying information does not provide sufficient assurance for authorizing a sensitive transaction like a wire transfer.

  • C. Correct.

    This is correct because out-of-band verification using trusted contact information or an approved authorization workflow is a best-practice control against voice-based social engineering. Independently contacting the executive through a known-good channel and following separation-of-duties or dual-approval procedures helps verify identity and intent before releasing funds.

  • D. Incorrect.

    This is incorrect because email alone is not a strong verification method for an urgent financial request. If the executive's email is compromised, or if the attacker is also conducting a parallel email attack, written confirmation may still be fraudulent. A lack of bounce-back only indicates message delivery status, not identity or authorization.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam