SY0-701 exam dumps

SY0-701 practice question 78 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 78

Single answer

A company's finance clerk receives an email that appears to come from the CEO, who is traveling overseas. The message says a confidential acquisition is underway and instructs the clerk to urgently wire $48,000 to a new vendor within the next hour. The sender display name matches the CEO, but the email domain is "compaany.com" instead of the company's legitimate domain, "company.com." The message also pressures the clerk not to call because the CEO is "in meetings all day." Which of the following best describes this attack?

  1. A

    Business email compromise using impersonation and typosquatting

  2. B

    A watering hole attack targeting the finance department

  3. C

    Smishing that uses brand impersonation to steal banking credentials

  4. D

    Vishing with a pretext designed to obtain multifactor authentication codes

Show answer and explanation

Correct answer: A

Explanation

The best answer is business email compromise using impersonation and typosquatting. BEC commonly targets finance and payroll personnel by abusing trust in executives, vendors, or business partners to trigger unauthorized payments or disclosure of sensitive data. In this case, the attacker uses impersonation by pretending to be the CEO and typosquatting by registering a domain visually similar to the legitimate one. The secrecy and urgency are intended to suppress normal verification procedures. Security best practices recommended by organizations such as CISA and the FBI for BEC defense include out-of-band verification of payment requests, dual approval for wire transfers, user awareness training on look-alike domains, and technical controls such as email authentication (SPF, DKIM, and DMARC). This question tests recognition of the social engineering pattern rather than just terminology.

  • A. Correct.

    Correct. This is a classic business email compromise (BEC) scenario: an attacker impersonates a trusted executive to manipulate an employee into making a fraudulent payment. The altered domain, "compaany.com," is a typosquatted look-alike domain intended to evade casual inspection. The urgency, secrecy, and request to bypass normal verification are common social engineering traits associated with BEC.

  • B. Incorrect.

    Incorrect. A watering hole attack involves compromising a website that the target group commonly visits, then using that site to infect or exploit visitors. In this scenario, the attacker is sending a fraudulent email and attempting to induce a wire transfer, not luring the victim to a compromised trusted website.

  • C. Incorrect.

    Incorrect. Smishing is phishing delivered through SMS or text messaging. This scenario involves email, not text messages. Although impersonation is present, there is no indication of a mobile text-based lure or an attempt to harvest credentials through SMS.

  • D. Incorrect.

    Incorrect. Vishing is voice-based social engineering, usually conducted over phone calls or voicemail. Pretexting can be part of many attacks, but the main facts here point to a fraudulent email from a spoofed or look-alike domain requesting funds. There is also no request for MFA codes in the scenario.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam