Courseiva
Security Program Management and OversighthardMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

An accounts payable specialist receives an email inside an existing vendor thread that asks for a last-minute bank-account change before a payment run. The wording is professional, the signature matches, and the request is urgent. Which three actions should the specialist take? Select three.

⚠ Common exam trap

Candidates often assume a professional-looking email with a matching signature is sufficient proof of authenticity, overlooking that BEC attacks can perfectly replicate these details within a compromised thread.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the request through a known out-of-band contact method for the vendor.

Verifying the request through a known out-of-band contact method (e.g., a phone call to a previously documented vendor number) directly mitigates the risk of business email compromise (BEC). Attackers often hijack or spoof legitimate email threads, so in-band verification (replying within the thread) is unreliable. This aligns with the principle of dual control and independent verification for sensitive financial changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify the request through a known out-of-band contact method for the vendor.

    Why this is correct

    A compromised email thread is fully controlled by the attacker, so any reply or embedded link stays within an untrusted channel. Using a known out-of-band method—such as a phone number previously documented in the vendor master file, or a secure portal that was already established—creates a second, independent channel the attacker cannot intercept or modify. This directly defeats business email compromise (BEC) by verifying the authenticity of the bank detail change before any sensitive update is executed.

  • Pause the payment and require secondary approval before any bank details are updated.

    Why this is correct

    Requiring a second approver enforces separation of duties, ensuring that no single compromised mailbox or user can authorize a fraudulent payment change. This control introduces a human checkpoint that can spot anomalies, and it creates an audit trail that proves the change was reviewed. It also buys time for the organization to validate the request, significantly narrowing the window in which a fraudulent transfer can be initiated.

  • Report the message through the security and vendor-validation process.

    Why this is correct

    Reporting through the security and vendor-validation process allows incident response teams to correlate indicators of compromise—such as the sender address, phishing links, or language patterns—with other known campaigns and proactively block similar messages across the organization. It also enables the company to contact the vendor directly through trusted channels to confirm whether the requested change is legitimate, preventing other departments from falling for the same scam. This transforms a single suspicious email into actionable threat intelligence rather than leaving it as an isolated action.

  • Reply in the same thread because the address and signature look legitimate.

    Why it's wrong here

    An attacker who has compromised a legitimate vendor mailbox (or spoofed the domain) can continue the conversation, forge headers, and alter subsequent instructions, so replying provides zero cryptographic or procedural proof of identity. Display names, domains, and signatures can all be recreated exactly, and the entire conversation remains under attacker control. Without a separate, known communication channel, replying only confirms the attacker’s ability to impersonate the vendor and does nothing to validate the request.

  • Process the change immediately to avoid delaying the vendor relationship.

    Why it's wrong here

    Urgency is a classic social-engineering trigger in BEC attacks, and acting without verification turns a suspicious request into a confirmed financial loss; once a wire or ACH transfer is initiated, funds are rarely recoverable. The short delay required for validation is almost always less costly than the fraudulent payment itself, and legitimate vendors expect verification for sensitive banking changes. Immediate processing bypasses all detective and preventive controls, leaving the organization fully liable for the loss.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.