What Scenario Best Describes a Business Email Compromise Attack?

Which of the following scenarios describes a possible business email compromise attack?

  1. An employee receives a gift card request in an email that has an executive’s name in the display field of the email.
  2. Employees who open an email attachment receive messages demanding payment in order to access files.
  3. A service desk employee receives an email from the HR director asking for log-in credentials to a cloud administrator account. Source Reference Answer
  4. An employee receives an email with a link to a phishing site that is designed to look like the company’s email portal.

Community Votes

C
57%
A
43%

57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether candidates recognize that BEC extends beyond financial fraud to include targeted social engineering aimed at harvesting privileged credentials or bypassing authentication mechanisms.

This question evaluates understanding of Business Email Compromise (BEC) versus other email-based attacks. The community consensus supports option C, highlighting that BEC leverages trusted authority figures to manipulate employees into compromising security controls or credentials.

Candidates frequently select option A, associating BEC strictly with executive impersonation for gift card purchases. While widely recognized in industry as CEO fraud, CompTIA considers option C a stronger example because it directly targets privileged access through a trusted internal role, aligning with modern BEC objectives focused on initial system access rather than immediate financial payout.

Community Discussion (55 comments)

lauren2wright 👍 24
C. In a BEC attack, the attacker typically impersonates a high-ranking executive or authority figure within the organization and requests sensitive information or actions from employees. In this case, the HR director is requesting log-in credentials for a cloud administrator account, which is a classic example of BEC where the attacker seeks to gain access to privileged accounts through deception.
ZhugeLiang 👍 1 Selected: A
Email account compromise (EAC) vs BEC In many cases the objective of a BEC attacker and EAC attacker are the same: They want to steal money, data or other sensitive information. However, the key difference is that in a BEC attack, the hacker is merely posing as a trusted figure, such as a business executive, lawyer, or important vendor, usually via a spoofed email account. That person then attempts to direct an employee or other person to take a given action, such as wiring funds to the attacker’s account. In EAC attacks, however, the attacker breaches a legitimate email account and acts as the owner of that account. With access to real credentials, the actor is able to conduct fraudulent activity and bypass multi-factor authentication tools.
IT_dude_in_training 👍 1 Selected: C
Business Email Compromise (BEC) typically involves attackers impersonating a trusted authority—like an executive, HR director, or other high-level personnel—to deceive employees into taking actions that compromise security or financial assets. In Option C, the email appears to be from someone in a position of trust (the HR director) making a request that seems unusual (asking for login credentials), which fits the classic BEC pattern.
Brian_Douglas 👍 1 Selected: A
I believe it is A, as they muddled the question to state "display field" and not simply From: It best meets a BEC attach when you change the question to read from the CEO.
Bik047 👍 1 Selected: A
Answer is A. Option C is more as credential harvesting
Woodiynho 👍 1 Selected: A
A and C are correct, but A is the most common example of a BEC attack; cuz this is a classic BEC attack where an attacker spoofs an executive's email and asks for gift cards or money.
JackExam2025 👍 1 Selected: A
This is a typical BEC scenario, where an attacker impersonates an executive and asks for a gift card or financial transfer, often in an urgent or confidential manner. C - Is an attempt to steal login credentials, but it is not a typical BEC attack. BEC usually involves financial manipulation or social engineering related to authority figures, not credential theft.
iamose 👍 1 Selected: A
An employee receives a gift card request in an email that has an executive’s name in the display field of the email, as it describes a Business Email Compromise (BEC) attack. BEC relies on social engineering rather than malware or phishing links, where attackers impersonate executives or trusted individuals to manipulate employees into making financial transactions, such as purchasing gift cards or wiring money. Unlike phishing, BEC does not involve fake login pages but instead creates a sense of urgency to pressure the target.
lloocckkeeyy 👍 1 Selected: A
The best answer is A. The email request for a service implies that the email account has already been compromised. In answer C, the HR director is requesting information in an "attempt" to compromise the user's account. Flagging said email would mean that the attack has been averted and NOT compromised.
Cyberfox9001 👍 1 Selected: C
At first, I was going to pick A but C fits the description more. In this case, why would a HR Coordinator ask for the login credentials of an employee. If they needed information, they could've asked the manager or director but most times they can access themselves.
Hasss 👍 1 Selected: C
A prime example of a BEC,
Leek23 👍 1 Selected: A
A. An employee receives a gift card request in an email that has an executive’s name in the display field of the email. This scenario describes a typical Business Email Compromise (BEC) attack, where a malicious actor impersonates an executive or other trusted individual in order to deceive an employee into taking a specific action, such as purchasing gift cards or transferring funds. In BEC attacks, the attacker often uses social engineering to exploit the authority of a known figure within the company. Other options describe different types of cyberattacks: B is likely a ransomware attack (demanding payment for access to files). C could be a phishing or credential harvesting attack. D is an example of a phishing attack aimed at stealing login credentials.
Innana 👍 2 Selected: A
We had that question while doing CompTIA course and A was the answer
Maximux1804 👍 2 Selected: A
A. This scenario describes a Business Email Compromise (BEC) attack, which is a type of phishing attack that relies on social engineering. In a BEC attack, attackers impersonate a trusted individual (often an executive) and use their name or email address to request sensitive information, payments, or, as in this case, gift cards. These attacks often rely on urgency and authority to trick employees into acting without verifying the request.
MasiEB 👍 1 Selected: A
C is not correct because it is an example of credential harvesting
[Removed] 👍 3 Selected: C
A. executive name is something you can find online. B/D are just phishing. C actually involves a high ranking member's intranet email address which indicates a compromise in the security.
CEEJAY83 👍 1 Selected: B
I will stick with B. Receiving an attachment, or file in an email, does not compromise a system. But opening the file or attachment in the email does.
EngAbood 👍 1 Selected: D
all answer correct , what is this question :(
JRCHENRY 👍 1 Selected: C
they are trying to impersonate someone within the company in order to trick that person into sharing thier credentials
Innana 👍 1 Selected: A
A is the correct answer. C is only credential harvesting and not a business email compromise
HazyG5224 👍 2
Answer is C. A doesn’t make sense to me think about it people can change there display name that’s the Key word that stood out. If it mention the email of an executive that’s different, but it didn’t the only one that make sense when talking about a business comprise is C because if you get a email from HR that’s something you would be familiar with but requesting my logins are kind of of that sets a red flag in the company
NXGENSYSEN 👍 1
An email where the Executive name is in the field is quite different than receiving an email from. Here they are not mentioning which field, however an email from means it is originate from someone. Therefore the correct can only be C. i
Lacuna 👍 3 Selected: C
C. Requires compromise of the business email. Answer A can be performed with publicly available information
Markeze 👍 1
Business Email Compromise (BEC) attacks often involve impersonating high-ranking individuals within a company to trick employees into divulging sensitive information or performing unauthorized actions. In this scenario, the HR director's email is being used to request login credentials, which could lead to a serious security breach.
tamdod 👍 1
It is C. Email from HR directed to someone at the helpdesk. A is targeted at a employee, who is this employee, do they have access to company funds to purchase gift cards? A to me is phishing.
Qasim_Ali_Cheema 👍 1
A business email compromise (BEC) attack is a phishing attack that targets employees with access to company funds or sensitive information. The attacker impersonates a trusted person, such as an executive, a vendor, or a client, and requests a fraudulent payment, a wire transfer, or confidential data. The attacker often uses social engineering techniques, such as urgency, pressure, or familiarity, to convince the victim to comply with the request. In this scenario, option A describes a possible BEC attack, where an employee receives a gift card request in an email with an executive’s name in the display field of the email. The email may look like it is coming from the executive, but the actual email address may be spoofed or compromised. The attacker may claim that the gift cards are needed for a business purpose, such as rewarding employees or clients, and ask the employee to purchase them and send the codes. This is a common tactic used by BEC attackers to steal money from unsuspecting victims.
PAWarriors 👍 1 Selected: C
Correct answer is C. Business Email Compromise (BEC) is a Sophisticated type of phishing attack that usually targets businesses by using one of their internal email accounts to get other employees to perform some kind of malicious actions on behalf of the attacker.
BugG5 👍 1 Selected: A
A business email compromise (BEC) attack is a type of phishing attack that targets employees who have access to company funds or sensitive information. The attacker impersonates a trusted person, such as an executive, a vendor, or a client, and requests a fraudulent payment, a wire transfer, or confidential Idata. The attacker often uses social engineering techniques, such as urgency, pressure, or familiarity, to convince the victim to comply with the request
Grouthorax 👍 3
Both A and C can be classified as a BEC because they both impersonate an executive or high-level authority. However, with the details we are given, we should assume that the attacker in scenario A is targeting only the recipient to fool them into sending them money. In scenario C, the attacker is trying to gain access to an administrative account which would likely cause a lot more harm to an organization.
pedrwc7 👍 4 Selected: C
A. An employee receives a gift card request in an email that has an executive’s name in the display field of the email. (It did not state that the email is from a company internal email address account) B. Employees who open an email attachment receive messages demanding payment in order to access files. (It did not state that the email is from a company internal email address account) C. A service desk employee receives an email from the HR director asking for log-in credentials to a cloud administrator account. (It did state that the email is from a company internal email address account) D. An employee receives an email with a link to a phishing site that is designed to look like the company’s email portal. (It did not state that the email is from a company internal email address account)
dbrowndiver 👍 1
Explanation: A. An employee receives a gift card request in an email that has an executive’s name in the display field of the email is a classic example of a Business Email Compromise (BEC) attack. Here's why: Impersonation of Authority: The attacker impersonates an executive by using their name in the display field, creating a sense of urgency and authority. This tactic exploits the trust and authority associated with high-ranking individuals, prompting the target to comply without question. No Malware or Links: BEC attacks typically do not involve malware, malicious links, or attachments. Instead, they rely on social engineering to manipulate the victim into performing actions such as wiring money or purchasing gift cards. Targeted and Personal: The request is specific and personal, aimed at an individual within the organization who is likely to fulfill such a request without verification. This makes it a sophisticated form of phishing that targets specific roles or individuals with access to resources.
tladytea 👍 4 Selected: D
C. A service desk employee receives an email from the HR director asking for log-in credentials to a cloud administrator account. Here’s the reasoning: • Business Email Compromise (BEC) attacks typically involve a cybercriminal impersonating a trusted person, such as an executive or a manager, to trick employees into divulging sensitive information, making unauthorized wire transfers, or performing actions that compromise the security of the organization. • Scenario C fits this description because it involves an attacker impersonating the HR director to trick a service desk employee into providing sensitive log-in credentials. This is a common tactic in BEC attacks.
mr_Mojo 👍 1 Selected: C
I believe the answer is C. In the A scenario, an employee receives an email "that has an executive’s name in the display field" which does not necessarily mean that it came from an executive, while in C scenario it explicitly says that an email came from the HR director.
ezmoney 👍 2
The Answer is A: Read carefully...The attacker impersonates an executive or high-level authority within the company to deceive employees into taking actions like sending money. This scenario describes an attempt to trick employees into purchasing gift cards by pretending to be an executive, which is a classic example of BEC. Example: An attacker sends an email claiming to be from the CEO asking the recipient to buy gift cards and send the details back, leveraging the EXECUTIVE'S NAME to create a sense of urgency and authority.
shaunenotsean 👍 2
Answer is A. I first picked "C", but the key words in the question is "Gift card Request", seriously, why would an executive REQUEST a gift card from a subordinate?
chadbigman 👍 1
Common Types of BEC Attacks: CEO Fraud: The attacker impersonates a high-ranking executive, instructing an employee to transfer funds to a fraudulent account.
AbdullahMohammad251 👍 4 Selected: C
Option A describes an executive whaling attack Option B describes a ransomware attack Option D describes a phishing attack to harvest credentials Option C describes a BEC attack. Business email compromise (BEC) attacks involve an attacker gaining access to a legitimate business email account or impersonating a trusted figure within an organization to deceive employees into taking actions that compromise security. The service desk employee received an email from the legitimate HR director account. This means the HR director's email account has been compromised, and the attacker is attempting to access sensitive information by requesting login credentials from the service desk employee.
Etc_Shadow28000 👍 2 Selected: C
A business email compromise (BEC) attack typically involves an attacker impersonating a legitimate business email account to deceive an organization or its employees into making unauthorized transactions or divulging sensitive information. A. - This is a common form of BEC, where the attacker impersonates an executive to request a gift card purchase or other financial action. B. - This describes a ransomware attack, not a BEC. Ransomware typically encrypts files and demands a ransom for decryption. C. - This scenario is a BEC attack, where the attacker impersonates an HR director to gain sensitive credentials. D. - This describes a phishing attack. While phishing can be part of a BEC attack, it is not a BEC attack itself unless it involves the specific impersonation and fraudulent intent typically seen in BEC. The scenario that best describes a possible business email compromise attack is: C.
Gadoof 👍 2
It's A because THE Classic BEC attack comes in the form of an attacker emailing an internal asking for them to purchase gift cards with the company debit card for a 'future meeting that they don't have time to handle.' This is a scam as it's not really the CFO or whoever and they'll ask you to leave the gift cards 'outside' or somewhere where the attacker can take them. It's also so low in monetary value that nobody cares to investigate, thus enabling the attackers to continue operating with impunity. C is way more than a BEC.
MahiMahiMahi 👍 1 Selected: C
C for sure, anyone can look up an executives name but receiving an email from the actual HR director's email address and not a look alike is a bigger threat.
Boats 👍 2 Selected: C
C is the correct answer. A is a close second but beware the wording on this one. Answer A indicates this is a spoofed account while answer C appears to be an actual compromise of the HR directors email where an attacker has control.
MAKOhunter33333333 👍 4 Selected: A
Everywhere I read from credible online sources like FBI, CloudFlare, Cisco, etc., state that BEC is financially motivated and is the main goal, not compromising credentials. Professor Messer even mentions financial fraud.
Lanka22 👍 1 Selected: C
Obviously, it's C Why does HR need a Cloud Admin Password
oluabi.salami 👍 1
BEC is a mail seeming to have come from a known identifiable colleague. C is right.
Abcd123321 👍 1 Selected: C
Business Email Compromise (BEC) ● Sophisticated type of phishing attack that usually targets businesses by using one of their internal email accounts to get other employees to perform some kind of malicious actions on behalf of the attacker ● Taking over a legitimate business email accounts through social engineering or cyber intrusion techniques to conduct unauthorized fund transfers, redirect payments, or steal sensitive information
hasquaati 👍 1 Selected: C
C for me on this one. A could possibly be a BEC, however the attacker is only impersonating the "Name" of the CEO, where as the HR Director has had his/her email actually compromised.
shady23 👍 1 Selected: A
A. An employee receives a gift card request in an email that has an executive’s name in the display field of the email.
AutoroTink 👍 1 Selected: C
While the scenario in option A could be part of a broader phishing or social engineering attempt, it does not specifically align with the typical methods and objectives of a BEC attack, which is why option C is a more fitting example of a BEC scenario.
cri88 👍 1 Selected: C
C is the right one
rjbb 👍 1 Selected: C
The answer is C, the question states - "Which of the following scenarios describes a possible business email compromise attack" This implies that someone in the business has had their email COMPROMISED, IE - the threat actor is using their email to impersonate them. So the solution should be C, as they are using the HR Directors email to log in to a cloud admin account.
Xavierallen9711 👍 1 Selected: C
I’d say C
shady23 👍 2
A. An employee receives a gift card request in an email that has an executive’s name in the display field of the email.
Yoez 👍 2
For me is : C
shady23 👍 2 Selected: A
A. An employee receives a gift card request in an email that has an executive’s name in the display field of the email.
Mehsotopes 👍 2 Selected: A
This describes a possible business email compromise attack, because it displays the compromised name of the executive in in the display field. Business Email Compromise (BEC) is an advanced phishing attack that leverages internal email accounts within a company to manipulate employees into carrying out malicious actions for the attacker.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Defining Business Email Compromise

Business Email Compromise (BEC) is a sophisticated form of social engineering where attackers impersonate trusted individuals—such as executives, directors, or vendors—to manipulate employees into taking actions that compromise organizational security or finances. Unlike broad phishing campaigns, BEC is highly targeted and relies heavily on contextual trust and authority.

Why Option C is Correct

Option C describes a service desk employee receiving a credential request from an apparent HR director. This scenario exemplifies BEC because it exploits the inherent trust placed in internal leadership roles. By posing as the HR director, the attacker leverages urgency and positional authority to coerce a technical employee into disclosing high-privilege credentials. In CompTIA’s framework, BEC is evaluated based on its operational impact and use of authoritative deception, making privilege escalation via email a quintessential BEC tactic.

Why the Other Options Are Incorrect

Option A depicts executive impersonation for gift cards, commonly known as CEO fraud. While the broader cybersecurity industry often groups this under BEC, CompTIA differentiates it in this context as a simpler social engineering attempt lacking the targeted privilege exploitation focus. Additionally, the phrasing “display field” suggests potential spoofing without confirmed compromise intent, making it less definitive than C. Option B describes ransomware delivery via malicious attachments, where victims face encryption and payment demands. This falls under malware/ransomware categories, not BEC. Option D illustrates credential phishing via a malicious URL designed to mimic a legitimate portal. This is classified as phishing or spear phishing, relying on deceptive links rather than authoritative email deception.

Community Consensus & Exam Nuance

As noted in community discussions, many candidates initially lean toward A due to its prevalence in real-world news. However, SY0-701 emphasizes enterprise risk management and access control. Option C better reflects the certification’s focus on how BEC campaigns are used to establish persistent footholds by harvesting administrative credentials through trusted channels.

Official Reference

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide