nerdexam
CompTIA

220-1002 · Question #628

A user received a call from a bank to confirm a wire transfer; however, the user created no such request. While troubleshooting, a technician discovers there are rules on the user's account that are…

The correct answer is C. hijacked email. This is a classic example of hijacked email (also called email account compromise). An attacker gained unauthorized access to the user's email account and created inbox rules to silently forward bank emails to an external attacker-controlled address and delete the originals…

Networking

Question

A user received a call from a bank to confirm a wire transfer; however, the user created no such request. While troubleshooting, a technician discovers there are rules on the user's account that are forwarding the emails to an external email address and deleting the emails from the bank. This is an example of:

Options

  • Aspam email.
  • Binvalid certificates.
  • Chijacked email.
  • Dbrowser pop-ups.

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    10% (4)
  • C
    76% (31)
  • D
    12% (5)

Explanation

This is a classic example of hijacked email (also called email account compromise). An attacker gained unauthorized access to the user's email account and created inbox rules to silently forward bank emails to an external attacker-controlled address and delete the originals from the user's mailbox. This allows the attacker to intercept financial communications (like wire transfer confirmations) without the account owner's knowledge. This is not spam (A), which is unsolicited bulk mail; not invalid certificates (B), which relate to SSL/TLS trust; and not browser pop-ups (D), which are website-based. The defining indicators here are the unauthorized forwarding rules and deletion rules set inside the compromised account.

Topics

#email hijacking#email forwarding rules#account compromise#social engineering

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice