SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A finance analyst receives an email that appears to come from the CFO. It references a real project, asks for an urgent wire transfer to a "new vendor account," and says to avoid the normal approval workflow because the deal is time-sensitive. What is the best immediate response?
⚠ Common exam trap
SY0-701 often tests the misconception that replying to or forwarding a suspicious email is a safe way to verify it, when the correct action is out-of-band verification via a known-good channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the request using a known-good contact method and report the message as suspicious.
The best immediate response is to verify the request using a known-good contact method (e.g., a phone number from the corporate directory) and report the message as suspicious. This defeats the impersonation attempt because the attacker cannot control the out-of-band channel. It also follows the principle of verifying unusual or urgent financial requests through a separate trusted path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reply to the email asking for additional payment details and wait for a response.
Why it's wrong here
Replying to the email keeps the conversation inside an attacker-controlled transport path; the reply-to address or the entire thread may be monitored or redirected by the threat actor. Waiting for a response gives the attacker more time to craft a convincing follow-up, but it does not create any evidence that the original sender is legitimate. Verification must occur through a separate, known-good channel, such as a phone number already on file, never by continuing to engage the same email thread.
- ✗
Process the transfer quickly because the message appears to come from an executive.
Why it's wrong here
Business email compromise (BEC) attackers routinely spoof executive display names, send from lookalike domains, or use a compromised executive inbox to generate a false sense of authority and urgency. The appearance of a high-ranking sender is not proof of authenticity; email headers can be forged, and legitimate-looking signatures can be replayed from previous messages. Acting quickly without independent, out-of-band verification bypasses standard payment controls and can cause an irreversible wire transfer, which is exactly the attacker's intended outcome.
- ✓
Verify the request using a known-good contact method and report the message as suspicious.
Why this is correct
The safest response is to independently verify the request through a trusted channel already on file, such as a known phone number or internal messaging system. That breaks the attacker’s control of the conversation and prevents a rushed financial error. Reporting the message also helps security staff search for related phishing attempts and protect other employees from a similar business email compromise attempt.
- ✗
Forward the email to another finance employee so someone else can confirm the request.
Why it's wrong here
Forwarding the message to another employee merely expands the exposure to the phishing or BEC campaign without adding any verification capability; the second employee has no better basis to judge the sender's authenticity than the first. If the attacker has already compromised an account or set mailbox rules, the forwarded email could be routed to the attacker or trigger automated replies that escalate the threat. The correct action is to isolate the original email and verify through a known-good contact method, then report it to security staff so they can analyze it without spreading it further through the organization.
Go deeper
Related to this question
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.