712-50 Question 259
Select 2Social Engineering, Phishing Attacks, Identity Theft (6 questions)A global manufacturing company has experienced a surge in highly targeted phishing emails impersonating senior executives and key suppliers. In one recent incident, an accounts payable manager received a convincing email that appeared to come from the CFO, requesting an urgent change to a supplier's bank details. The email passed basic spam checks, used accurate internal terminology gathered from social media, and led to a fraudulent payment before the deception was discovered. As the newly appointed CCISO, you have been asked to recommend the MOST effective set of actions to reduce the risk of similar social engineering and identity-based fraud attacks while maintaining business efficiency. Which TWO actions should be prioritized?
- A
Implement an out-of-band verification process for payment instruction changes and other high-risk financial requests
- B
Deploy and enforce email authentication controls such as SPF, DKIM, and DMARC, with monitoring and tuning
- C
Block all external emails that contain executive names in the display name or subject line
- D
Require annual security awareness training only for finance staff because they are the primary target of payment fraud
- E
Rely on the secure email gateway's anti-spam engine and increase its sensitivity to aggressively quarantine suspicious messages
Show answer and explanation
Correct answers: A, B
Explanation
The best answer is to prioritize both process control and technical control: out-of-band verification for high-risk requests and robust email authentication with SPF, DKIM, and DMARC. In real-world BEC and identity theft scenarios, the most damaging fraud often succeeds because attackers exploit trust and business processes, not just technical weaknesses. CCISO-level decision-making should therefore combine governance, process redesign, and technical safeguards.
Out-of-band verification is strongly aligned with anti-fraud best practices because it mitigates socially engineered requests to change bank details, payroll information, or payment destinations. Separately, SPF, DKIM, and DMARC are widely recognized email security standards that help prevent direct domain spoofing and provide reporting to identify abuse. Industry guidance from NIST and CISA emphasizes layered defense for phishing, including user awareness, strong business processes, email authentication, and verification procedures for sensitive requests. This layered approach is more effective than overreliance on spam filters or overly broad blocking rules, which can be bypassed or create unacceptable operational friction.
- A. Correct.
Correct. Out-of-band verification is one of the most effective controls against business email compromise (BEC), phishing-based payment diversion, and identity fraud. For high-risk transactions such as bank account changes, verification through a trusted secondary channel, such as calling a known number from a validated vendor record rather than using contact details from the email, directly addresses the social engineering tactic. This control is also operationally practical because it targets the highest-risk workflows rather than broadly slowing all communication.
- B. Correct.
Correct. SPF, DKIM, and DMARC together help reduce domain spoofing and improve visibility into unauthorized use of the organization's email domains. While they do not stop all phishing, especially when attackers use lookalike domains or compromised legitimate accounts, they are foundational email security controls that materially reduce impersonation risk and support monitoring, enforcement, and incident response. This is a strategic control expected at the executive level.
- C. Incorrect.
Incorrect. Blocking all external emails containing executive names in the display name or subject line is overly broad, easy to evade, and likely to create major business disruption and false positives. Attackers can change wording, use lookalike names, or compromise legitimate external accounts. A CCISO should favor risk-based controls that are resilient and sustainable rather than simplistic keyword-based blocking.
- D. Incorrect.
Incorrect. Limiting awareness training to finance staff reflects a narrow view of social engineering risk. While finance is a common target, attackers often target executives, HR, procurement, help desks, and general employees to gather information, steal credentials, or stage broader fraud. Best practice is role-based training for all staff, with enhanced training for high-risk groups, not annual-only training for one department.
- E. Incorrect.
Incorrect. Secure email gateways are important, but relying primarily on spam filtering is insufficient against targeted spear-phishing and BEC, which often contain no malware or obvious indicators and may pass technical filters. Increasing sensitivity may also disrupt legitimate business communication. Email filtering should complement, not replace, process controls and identity-focused defenses.