712-50 exam dumps

712-50 practice question 258 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 258

Single answerSocial Engineering, Phishing Attacks, Identity Theft (6 questions)

A global manufacturing company has experienced three business email compromise (BEC) incidents in two months. In each case, finance staff received convincing emails impersonating senior executives and were pressured to change supplier banking details. The emails passed basic spam filtering because they originated from look-alike domains and contained no malware. The board asks the CISO for the most effective risk-reduction strategy that can be implemented at the enterprise level without significantly slowing legitimate payment operations. Which action should the CISO prioritize?

  1. A

    Deploy a stricter anti-malware email gateway and block all messages with attachments from external domains

  2. B

    Require out-of-band verification and dual authorization for vendor bank account changes and high-risk payment requests

  3. C

    Increase password complexity requirements for finance staff and rotate their passwords every 30 days

  4. D

    Conduct a one-time phishing awareness campaign for the finance department and track completion rates

Show answer and explanation

Correct answer: B

Explanation

The scenario describes classic business email compromise, a form of phishing and social engineering in which attackers impersonate executives or trusted parties to manipulate financial processes. Because the emails are credible, malware-free, and sent from look-alike domains, technical filtering alone will not fully mitigate the threat. At the CCISO level, the most appropriate response is to implement governance and operational controls that reduce the likelihood of successful fraud despite deceptive messages. Requiring out-of-band verification for changes to vendor banking information and dual authorization for high-risk payments is aligned with established anti-fraud practices and with broader guidance from sources such as NIST cybersecurity awareness recommendations and CISA phishing guidance emphasizing verification of sensitive requests through trusted channels. This approach is stronger than relying only on password changes, malware controls, or one-time awareness training because it directly protects the business process most targeted by the attacker.

  • A. Incorrect.

    This is not the best priority for the described scenario. The attacks are business email compromise attempts using social engineering, look-alike domains, and no malware. A stricter anti-malware gateway focused on attachments would not address the core attack path. Blocking all external attachments would also create unnecessary business friction and still would not stop text-only impersonation emails.

  • B. Correct.

    This is the best answer. BEC attacks targeting payment changes are most effectively reduced by strong business-process controls, especially out-of-band verification using a trusted channel and dual authorization for bank detail changes or unusual payments. These controls directly address the social engineering objective even if the email appears legitimate, and they are widely recommended in anti-fraud and phishing guidance because they break the attack chain before money is transferred.

  • C. Incorrect.

    This is a plausible but incorrect response. Strong password practices are useful for account security, but the scenario does not indicate compromised passwords as the primary issue. The key problem is employee trust in fraudulent payment instructions. Tightening password complexity or frequent rotation would have limited effect on impersonation-based fraud and may increase user burden without materially reducing this specific risk.

  • D. Incorrect.

    Training is important, but a one-time awareness campaign is not the most effective enterprise-level control to prioritize here. Human-focused education alone is weaker than enforcing process-based controls for high-risk transactions. Completion tracking also measures attendance, not effectiveness. In BEC scenarios, executives should prioritize durable procedural safeguards over relying mainly on staff vigilance.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam