What Scenario Best Describes a Business Email Compromise Attack?
Which of the following scenarios describes a possible business email compromise attack?
Community Votes
57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether candidates recognize that BEC extends beyond financial fraud to include targeted social engineering aimed at harvesting privileged credentials or bypassing authentication mechanisms.
This question evaluates understanding of Business Email Compromise (BEC) versus other email-based attacks. The community consensus supports option C, highlighting that BEC leverages trusted authority figures to manipulate employees into compromising security controls or credentials.
Candidates frequently select option A, associating BEC strictly with executive impersonation for gift card purchases. While widely recognized in industry as CEO fraud, CompTIA considers option C a stronger example because it directly targets privileged access through a trusted internal role, aligning with modern BEC objectives focused on initial system access rather than immediate financial payout.
Community Discussion (55 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Defining Business Email Compromise
Business Email Compromise (BEC) is a sophisticated form of social engineering where attackers impersonate trusted individuals—such as executives, directors, or vendors—to manipulate employees into taking actions that compromise organizational security or finances. Unlike broad phishing campaigns, BEC is highly targeted and relies heavily on contextual trust and authority.Why Option C is Correct
Option C describes a service desk employee receiving a credential request from an apparent HR director. This scenario exemplifies BEC because it exploits the inherent trust placed in internal leadership roles. By posing as the HR director, the attacker leverages urgency and positional authority to coerce a technical employee into disclosing high-privilege credentials. In CompTIA’s framework, BEC is evaluated based on its operational impact and use of authoritative deception, making privilege escalation via email a quintessential BEC tactic.Why the Other Options Are Incorrect
Option A depicts executive impersonation for gift cards, commonly known as CEO fraud. While the broader cybersecurity industry often groups this under BEC, CompTIA differentiates it in this context as a simpler social engineering attempt lacking the targeted privilege exploitation focus. Additionally, the phrasing “display field” suggests potential spoofing without confirmed compromise intent, making it less definitive than C. Option B describes ransomware delivery via malicious attachments, where victims face encryption and payment demands. This falls under malware/ransomware categories, not BEC. Option D illustrates credential phishing via a malicious URL designed to mimic a legitimate portal. This is classified as phishing or spear phishing, relying on deceptive links rather than authoritative email deception.Community Consensus & Exam Nuance
As noted in community discussions, many candidates initially lean toward A due to its prevalence in real-world news. However, SY0-701 emphasizes enterprise risk management and access control. Option C better reflects the certification’s focus on how BEC campaigns are used to establish persistent footholds by harvesting administrative credentials through trusted channels.Official Reference
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →