How to Prevent Fraudulent Wire Transfers via Business Email Compromise?

Security Operations & Governance

An accounting clerk sent money to an attacker's bank account after receiving fraudulent instructions to use a new account. Which of the following would most likely prevent this activity in the future?

  1. Standardizing security incident reporting
  2. Executing regular phishing campaigns
  3. Implementing insider threat detection measures
  4. Updating processes for sending wire transfers Source Reference Answer

Community Votes

D
83%
B
17%

83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests your ability to distinguish between technical controls, training, and procedural safeguards, with the common trap being the selection of phishing simulations over direct process hardening.

This scenario highlights the importance of implementing robust procedural controls for financial transactions to mitigate business email compromise attacks. The community overwhelmingly agrees that updating wire transfer verification processes is the most effective preventive measure compared to technical or awareness-only solutions.

Candidates frequently choose regular phishing campaigns because they assume user education alone can stop sophisticated social engineering, overlooking that BEC attacks bypass standard email filters and require mandatory procedural verification like dual authorization or out-of-band confirmation.

Community Discussion (6 comments)

Etc_Shadow28000 👍 10 Selected: D
D. Updating processes for sending wire transfers Updating the processes for sending wire transfers would most likely prevent this type of activity in the future. This could include implementing additional verification steps, such as requiring multiple levels of approval, verifying new payment instructions through a separate communication channel, or implementing a callback procedure to confirm the authenticity of the instructions. Therefore, the correct answer is: D. Updating processes for sending wire transfers
braveheart22 👍 2 Selected: D
The Answer: D. Updating processes for sending wire transfers This approach directly addresses the root cause of the fraudulent transaction — the lack of a secure, verified process for handling wire transfers — and would help prevent similar incidents from occurring in the future.
dbrowndiver 👍 2 Selected: D
In this scenario, the option should be D because updating processes for sending wire transfers is the best choice, it directly tackles the procedural weakness that allowed the fraudulent transaction to occur. Implementing verification and approval procedures can prevent similar incidents by ensuring that all payment instructions are authenticated and verified before any money is transferred, thereby reducing the risk of fraud.
EfaChux 👍 3 Selected: B
The accounting clerk acted in ignorance. more phishing campaigns would have prevented the transfer
3396ee7 👍 2
A is the correct answer
Shaman73 👍 1 Selected: D
D. Updating processes for sending wire transfers

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Updating processes for sending wire transfers directly addresses the procedural vulnerability exploited in this business email compromise attack. By implementing mandatory controls such as dual approval, out-of-band verification, and callback procedures for new payee changes, organizations establish a defense-in-depth layer that neutralizes social engineering tactics. As noted in the top-voted discussion, these procedural safeguards ensure that payment instructions are authenticated through independent channels before funds are released.

Why the Other Options Are Wrong

Standardizing security incident reporting is reactive rather than preventive, meaning it documents breaches after they occur instead of stopping them. Regular phishing campaigns improve general security awareness but cannot guarantee compliance with critical financial workflows, as attackers often craft highly convincing, context-specific emails that bypass even trained employees. Insider threat detection focuses on malicious internal actors, whereas this scenario involves an external attacker manipulating a legitimate employee through deception.

Community Comment Notes

The majority of candidates correctly identified the updated process option, emphasizing that procedural updates like multi-level approvals and separate communication channel verification directly tackle the root cause. Several users highlighted that while phishing training is valuable, it does not replace strict financial controls required for high-risk transactions. One dissenting vote for incident reporting was dismissed by the group, as documentation lacks any preventive function for active fraud schemes. Overall, the consensus reinforces CompTIA’s emphasis on governance and procedural controls over purely technical or awareness-based fixes.

Official Reference

Exam Strategy

When faced with scenarios involving financial fraud or sensitive data handling, always prioritize procedural and administrative controls like approval workflows and verification steps over training or monitoring options if the question asks for prevention. CompTIA frequently tests the hierarchy of controls, so look for answers that mandate physical or logical separation of duties to break the attack chain.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide