Identifying Invoice Scams in Accounting

Threats and Vulnerabilities
Answer Correct answer: D — This scenario is an example of an invoice scam where attackers send fraudulent payment requests for services never performed.

An employee in the accounting department receives an email containing a demand for payment for services performed by a vendor. However, the vendor is not in the vendor management database. Which of the following is this scenario an example of?

  1. Pretexting
  2. Impersonation
  3. Ransomware
  4. Invoice scam Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The scenario combines impersonation techniques with a specific financial motive, distinguishing it from general pretexting by focusing on the fraudulent invoice aspect.

This question tests the ability to distinguish between social engineering tactics and financial fraud schemes. It establishes that fraudulent payment requests from non-existent vendors are classified as invoice scams.

Pretexting is often chosen because attackers create fake scenarios; however, when the specific goal is a fraudulent invoice for non-existent services, 'Invoice scam' is the precise term.

Community Discussion (6 comments)

[Removed] 👍 21
Since stoneface, rodwave, applebees, and most of the other people are gone ill carry on the tradition of giving correct answers. I'm not what ET needs but im what ET gets.
LayinCable 👍 1 Selected: D
Although this seems like a straight shot to a pretexting situation, the biggest takeaway would be where it says requesting payment for services from a vendor. AND that "vendor" was not on the approved vendor list/sheet. With that being said, it's a scam to get them to pay money for an empty receipt/service. So, it's D.
_deleteme_ 👍 2
Passed my exam today friends, this d was on there, I chose A. Also, all the PBQs were there as well.
gab2024 👍 4 Selected: D
Just took the exam & passed (3/31/2024). COMPTIA will actually give you the Module sections that you missed. This is on my exam Section (1.1). I aced section (1.1).
Hs1208 👍 1 Selected: D
In an invoice scam, attackers typically send fraudulent invoices or payment requests.
RedDog2 👍 1 Selected: D
Invoice fraud is a well-coordinated ploy in which an attacker attempts to scam a business into paying a fake invoice–or paying a legitimate invoice to a fake account–by impersonating a vendor or partner.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is D, Invoice scam. An invoice scam involves sending fraudulent invoices or payment requests to victims, often impersonating legitimate vendors. Since the vendor is not in the database and the request is for payment for services never performed, this fits the definition of an invoice scam perfectly.

Why the Other Options Are Wrong

Pretexting (A) is a broader social engineering technique where an attacker creates a fabricated scenario (pretext) to engage a victim. While an invoice scam uses pretexting, the specific act of demanding payment for fake services is best described as an invoice scam. Impersonation (B) is a component of the attack but does not describe the entire scheme. Ransomware (C) involves encrypting data and demanding payment, which is unrelated to this email scenario.

Community Comment Notes

Community consensus strongly supports D. Comments highlight that while the situation feels like pretexting due to the deception, the key element is the fraudulent invoice requesting payment for non-existent services. One commenter noted that CompTIA specifically categorizes this under Section 1.1 as an invoice scam.

Exam Strategy

When identifying threats, look for the specific outcome or mechanism described. If money is being stolen via fake bills or payment requests, think 'Invoice Scam' or 'Business Email Compromise' rather than just generic social engineering terms.

Frequently Asked Questions

Why isn't this considered Pretexting?

Pretexting is the broad method of creating a false scenario. The specific execution here—demanding payment for fake services—is an invoice scam.

How do I distinguish Invoice Scam from Ransomware?

Ransomware encrypts files and demands crypto. Invoice scams trick you into voluntarily paying a fake bill via wire or check.

Related Analysis

← Back to SY0-601 Study Guide