Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

How to Respond to a Business Email Compromise: Verify Out-of-Band

An accounts payable clerk receives an email that continues a real vendor conversation from last week. The sender domain is only one character different from the vendor's real address. The message says the invoice is overdue and asks the clerk to update the payment account before the end of the day. What is the best next action?

Quick Answer

The correct next action is to verify the request out-of-band using a known phone number or portal from previous records. This is because the email exhibits classic signs of a business email compromise (BEC) attack—specifically a typosquatted sender domain and urgent payment redirection—which means any reply or action taken within the compromised email channel could be intercepted by the attacker. On the Security+ SY0-701 exam, this scenario tests your understanding of social engineering and email-based threats, often appearing as a multi-step question where the trap is choosing to reply to the email or click a link in it. The core concept is that out-of-band verification bypasses the attacker’s control, ensuring you confirm legitimacy through a separate, trusted channel before any financial loss occurs. Remember the mnemonic “BEC = Bypass Email, Call” to recall that the safest response is always to pick up the phone or use a verified portal.

⚠ Common exam trap

Many exam-takers think opening the attachment to check payment details is a safe verification step, but in reality, attachments in phishing emails are a common vector for malware delivery, and the correct action is always to verify through a trusted, independent channel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the request using a known phone number or portal from previous records before taking action.

The email exhibits classic signs of a business email compromise (BEC) attack: a spoofed sender domain (typosquatting) and urgent payment redirection. The best next action is to verify the request out-of-band using a trusted phone number or portal from previous records, as this bypasses any compromised email channels and confirms the legitimacy of the request before any financial loss occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reply to the email asking for confirmation of the new bank details.

    Why it's wrong here

    Replying through the same message chain still trusts the potentially spoofed sender and can expose more details.

  • Verify the request using a known phone number or portal from previous records before taking action.

    Why this is correct

    Using a known out-of-band contact method confirms whether the request is legitimate without trusting the suspicious email path.

  • Forward the email to the vendor's entire contact list to warn them immediately.

    Why it's wrong here

    Broadcasting the message can spread the phishing attempt and may not preserve evidence for investigation.

  • Open the attached invoice to check whether the payment information matches past records.

    Why it's wrong here

    Opening attachments from a suspicious message increases risk and does not validate the sender's identity.

Go deeper

Related to this question

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An accounts payable specialist receives a reply inside an existing vendor email thread. The message uses the real invoice number, matches the vendor's usual tone, and asks the specialist to change payment instructions to a new bank account before the end of the day. The vendor later confirms its mailbox was compromised. What type of attack is most likely?

hard
  • A.Spear phishing, because the attacker targeted one employee with a convincing message.
  • B.Business email compromise through conversation hijacking, because the attacker used a compromised mailbox to alter a trusted thread.
  • C.Baiting, because the attacker tried to tempt the user with urgency and financial pressure.
  • D.Vishing, because the attacker is trying to persuade the user to change banking details.

Why B: This is a business email compromise (BEC) attack specifically using conversation hijacking. The attacker gained access to the vendor's legitimate email account and inserted a fraudulent reply into an existing, trusted email thread, leveraging the compromised mailbox to bypass the specialist's suspicion. This differs from standard spear phishing because the attacker did not craft a new email from a spoofed address but instead hijacked an ongoing, authenticated conversation.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.