CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

An accounts payable clerk receives an email that appears to come from the company's CFO, referencing a real ongoing vendor project and requesting an urgent wire transfer to a new bank account. The email address is one character off from the CFO's actual address. Which attack technique is being used?

  1. ABusiness email compromise
  2. BCredential stuffing
  3. CTyposquatting
  4. DWhaling
Show answer & explanation

Correct answer: A. Business email compromise

Business email compromise (BEC) involves impersonating an executive or trusted party via email, often using a spoofed or lookalike address and contextual details, to trick an employee into transferring funds. Whaling specifically targets high-value executives as victims, not as impersonated senders; typosquatting refers to domain-based deception generally, while BEC is the specific financial fraud scenario described.

Why the other options are wrong

  • B. Wrong: no stolen credentials or login attempts are described.
  • C. Wrong: typosquatting is a broader domain-registration tactic, not the specific attack name here.
  • D. Wrong: whaling targets executives as the victim, not clerks.

Business Email Compromise (BEC)

A social engineering attack where an attacker impersonates an executive or trusted vendor via email to trick an employee into transferring funds or sensitive data.

  • Often uses lookalike domains or compromised accounts
  • Relies on urgency and authority to bypass scrutiny
  • Commonly targets finance/accounts payable staff

Memory trick: BEC: Boss Emails Cash-request, but it's fake.

More Threats, Vulnerabilities, and Mitigations questions