How to Respond to a Business Email Compromise: Verify Out-of-Band
An accounts payable clerk receives an email that continues a real vendor conversation from last week. The sender domain is only one character different from the vendor's real address. The message says the invoice is overdue and asks the clerk to update the payment account before the end of the day. What is the best next action?
Quick Answer
The correct next action is to verify the request out-of-band using a known phone number or portal from previous records. This is because the email exhibits classic signs of a business email compromise (BEC) attack—specifically a typosquatted sender domain and urgent payment redirection—which means any reply or action taken within the compromised email channel could be intercepted by the attacker. On the Security+ SY0-701 exam, this scenario tests your understanding of social engineering and email-based threats, often appearing as a multi-step question where the trap is choosing to reply to the email or click a link in it. The core concept is that out-of-band verification bypasses the attacker’s control, ensuring you confirm legitimacy through a separate, trusted channel before any financial loss occurs. Remember the mnemonic “BEC = Bypass Email, Call” to recall that the safest response is always to pick up the phone or use a verified portal.
⚠ Common exam trap
Many exam-takers think opening the attachment to check payment details is a safe verification step, but in reality, attachments in phishing emails are a common vector for malware delivery, and the correct action is always to verify through a trusted, independent channel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the request using a known phone number or portal from previous records before taking action.
The email exhibits classic signs of a business email compromise (BEC) attack: a spoofed sender domain (typosquatting) and urgent payment redirection. The best next action is to verify the request out-of-band using a trusted phone number or portal from previous records, as this bypasses any compromised email channels and confirms the legitimacy of the request before any financial loss occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reply to the email asking for confirmation of the new bank details.
Why it's wrong here
Replying engages the attacker directly and confirms the mailbox is live; the lookalike domain means the response reaches the fraudster, not the vendor. Verifying by phone using a previously known number is correct. Replying is tempting because confirming details feels diligent, but it is the standard way business email compromise succeeds.
- ✓
Verify the request using a known phone number or portal from previous records before taking action.
Why this is correct
The lookalike domain and urgency indicate a business email compromise attempt. Verifying the payment change through a known phone number or portal from previous records, rather than replying to the message, confirms legitimacy out of band before any action is taken.
- ✗
Forward the email to the vendor's entire contact list to warn them immediately.
Why it's wrong here
Broadcasting the suspicious message to the vendor's whole contact list spreads potential malware links and discloses the incident without verification, and it does not stop the fraudulent payment. Forwarding warnings is tempting as a good-citizen reflex, but reporting to the security team and the real vendor through known channels is correct.
- ✗
Open the attached invoice to check whether the payment information matches past records.
Why it's wrong here
Opening the attachment executes whatever payload it carries, including macros or exploit code, on the clerk's workstation. Inspecting invoices is tempting because it appears to verify payment details against records, but attachments from a lookalike domain must be treated as hostile and reported unopened.
Go deeper
Related to this question
Learn chapter
Typosquatting and Domain Hijacking
Key term
Business email compromise
Business email compromise is a sophisticated cyberattack where a criminal impersonates a trusted person or organization via email to trick the victim into transferring money or revealing sensitive information.
Key term
Typosquatting
Typosquatting is a cyberattack where attackers register domain names that are common misspellings of popular websites to trick users into visiting fraudulent sites.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An accounts payable specialist receives a reply inside an existing vendor email thread. The message uses the real invoice number, matches the vendor's usual tone, and asks the specialist to change payment instructions to a new bank account before the end of the day. The vendor later confirms its mailbox was compromised. What type of attack is most likely?
hard- A.Spear phishing, because the attacker targeted one employee with a convincing message.
- ✓ B.Business email compromise through conversation hijacking, because the attacker used a compromised mailbox to alter a trusted thread.
- C.Baiting, because the attacker tried to tempt the user with urgency and financial pressure.
- D.Vishing, because the attacker is trying to persuade the user to change banking details.
Why B: This is a business email compromise (BEC) attack specifically using conversation hijacking. The attacker gained access to the vendor's legitimate email account and inserted a fraudulent reply into an existing, trusted email thread, leveraging the compromised mailbox to bypass the specialist's suspicion. This differs from standard spear phishing because the attacker did not craft a new email from a spoofed address but instead hijacked an ongoing, authenticated conversation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.