Question 986 of 1,013
SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A finance analyst receives an email that appears to come from the CFO. It references a real project, asks for an urgent wire transfer to a "new vendor account," and says to avoid the normal approval workflow because the deal is time-sensitive. What is the best immediate response?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the request using a known-good contact method and report the message as suspicious.
The best response is to verify the request through a known, trusted communication path and then report it. In a spear phishing or business email compromise scenario, the attacker relies on urgency, authority, and familiarity to bypass normal controls. A separate phone call, chat message, or in-person confirmation using an existing contact list provides stronger assurance than any reply to the suspicious email itself. Why others are wrong: Replying, processing the transfer, or forwarding the message all keep the workflow inside the attacker’s channel and increase the chance of fraud. None of those actions independently validate the sender’s identity or the payment change request. The key security habit is to stop, verify outside the email thread, and escalate the suspicious communication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reply to the email asking for additional payment details and wait for a response.
Why it's wrong here
Replying to the email keeps the conversation inside an attacker-controlled transport path; the reply-to address or the entire thread may be monitored or redirected by the threat actor. Waiting for a response gives the attacker more time to craft a convincing follow-up, but it does not create any evidence that the original sender is legitimate. Verification must occur through a separate, known-good channel, such as a phone number already on file, never by continuing to engage the same email thread.
- ✗
Process the transfer quickly because the message appears to come from an executive.
Why it's wrong here
Business email compromise (BEC) attackers routinely spoof executive display names, send from lookalike domains, or use a compromised executive inbox to generate a false sense of authority and urgency. The appearance of a high-ranking sender is not proof of authenticity; email headers can be forged, and legitimate-looking signatures can be replayed from previous messages. Acting quickly without independent, out-of-band verification bypasses standard payment controls and can cause an irreversible wire transfer, which is exactly the attacker's intended outcome.
- ✓
Verify the request using a known-good contact method and report the message as suspicious.
Why this is correct
The safest response is to independently verify the request through a trusted channel already on file, such as a known phone number or internal messaging system. That breaks the attacker’s control of the conversation and prevents a rushed financial error. Reporting the message also helps security staff search for related phishing attempts and protect other employees from a similar business email compromise attempt.
- ✗
Forward the email to another finance employee so someone else can confirm the request.
Why it's wrong here
Forwarding the message to another employee merely expands the exposure to the phishing or BEC campaign without adding any verification capability; the second employee has no better basis to judge the sender's authenticity than the first. If the attacker has already compromised an account or set mailbox rules, the forwarded email could be routed to the attacker or trigger automated replies that escalate the threat. The correct action is to isolate the original email and verify through a known-good contact method, then report it to security staff so they can analyze it without spreading it further through the organization.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: May 17, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.