SY0-701 exam dumps

SY0-701 practice question 77 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 77

Single answer

A company's accounting department receives an email that appears to come from the CEO, who is traveling internationally and says they are difficult to reach by phone. The message urgently instructs the accounts payable manager to change the bank account details for a long-time supplier before an afternoon wire transfer is sent. The sender display name matches the CEO, but the actual email domain is "executive-c0mpany.com" instead of the company's legitimate "executive-company.com" domain. The message also pressures the manager not to verify the change with the supplier because the CEO has "already handled it." Which attack best describes this scenario?

  1. A

    Business email compromise using brand impersonation and typosquatting

  2. B

    Watering hole attack targeting third-party vendor websites

  3. C

    Vishing attack using caller ID spoofing to impersonate the CEO

  4. D

    Smishing campaign using shortened links to steal credentials

Show answer and explanation

Correct answer: A

Explanation

The best answer is business email compromise (BEC) using brand impersonation and typosquatting. BEC commonly targets finance, payroll, and procurement staff by impersonating executives or trusted partners and creating urgency around payment changes, gift cards, or confidential data requests. The look-alike domain is a key indicator of typosquatting, where attackers register domains that visually resemble legitimate ones to deceive recipients. Security best practices recommend out-of-band verification for payment changes, callback procedures using known-good contact information, user awareness training on impersonation and urgency cues, and technical controls such as SPF, DKIM, and DMARC to reduce spoofing and improve email authenticity checks. These practices align with common guidance from NIST cybersecurity awareness and email security recommendations, as well as industry guidance on defending against BEC and social engineering.

  • A. Correct.

    Correct. This is a classic business email compromise (BEC) scenario: the attacker impersonates an executive, creates urgency, and attempts to redirect a legitimate payment by changing banking details. The use of a look-alike domain, "executive-c0mpany.com," is typosquatting, and pretending to be the CEO is brand/executive impersonation. These elements commonly appear together in real-world invoice and payment diversion fraud.

  • B. Incorrect.

    Incorrect. A watering hole attack involves compromising a website that the target routinely visits so malware or malicious content is delivered when users browse there. In this scenario, the attacker is sending a fraudulent email to manipulate a payment process, not compromising a trusted website.

  • C. Incorrect.

    Incorrect. Vishing is voice-based social engineering conducted over phone calls or voicemail. Although the email mentions the CEO is hard to reach by phone, the actual attack vector shown here is email. There is no evidence of a spoofed phone call or voice interaction in the scenario.

  • D. Incorrect.

    Incorrect. Smishing is phishing delivered by SMS or other text messaging platforms. The scenario centers on an email requesting a fraudulent bank account change, not a text message with a malicious link.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam