nerdexam
ACAMS

CAMS · Question #947

A customer of a financial Institution (Fl) complained that they had received multiple emails appearing to originate from the Fl urging them to click on a link or open a remittance attachment for…

The correct answer is D. Spear phishing. This scenario describes a targeted email-based attack where a customer was deceived into opening a malicious attachment, resulting in unauthorized fund transfers from their bank account.

New Developments in AML/CFT

Question

A customer of a financial Institution (Fl) complained that they had received multiple emails appearing to originate from the Fl urging them to click on a link or open a remittance attachment for confirmation. After opening the attachment, the customer later realized that funds had been systematically transferred out of their bank account without their knowledge Which type of cybercrime is described in this scenario?

Options

  • AVishing
  • BPharming
  • CSMSishing
  • DSpear phishing

How the community answered

(41 responses)
  • A
    12% (5)
  • B
    7% (3)
  • C
    2% (1)
  • D
    78% (32)

Why each option

This scenario describes a targeted email-based attack where a customer was deceived into opening a malicious attachment, resulting in unauthorized fund transfers from their bank account.

AVishing

Vishing refers to voice phishing conducted via telephone calls, not email-based deception involving malicious attachments.

BPharming

Pharming involves redirecting users from legitimate websites to fraudulent ones by corrupting DNS settings or hosts files, not through deceptive emails with attachments.

CSMSishing

SMSishing is phishing conducted via SMS text messages, not via email.

DSpear phishingCorrect

Spear phishing is a targeted form of phishing that uses personalized emails appearing to originate from a trusted source - such as the victim's own financial institution - to trick the recipient into opening malicious attachments or links. Unlike generic phishing, spear phishing is directed at a specific individual or organization, and the goal of stealing banking credentials or initiating unauthorized transfers is a defining characteristic of this attack type.

Concept tested: Identifying spear phishing as a targeted cybercrime method

Source: https://csrc.nist.gov/glossary/term/spear_phishing

Topics

#spear phishing#cybercrime typologies#social engineering#account takeover

Community Discussion

No community discussion yet for this question.

Full CAMS Practice