Medium2 marksMultiple Choice

ACCA · Question 09 · Syllabus C: Business functions, regulation and technology

[Section A] A fintech startup experiences a cyber-security incident. An employee receives an email appearing to be from the CEO, urgently requesting the transfer of funds to a new vendor. The employee complies, only to discover later that the email address was slightly misspelled and belonged to a malicious actor. What specific type of cyber-attack has occurred?

Answer options:

A.

Ransomware

B.

Distributed Denial of Service (DDoS)

C.

Spear-phishing

D.

Malware injection

How to approach this question

Identify the mechanism of the attack: a deceptive email targeting a specific employee and impersonating a specific executive.

Full Answer

C.Spear-phishing✓ Correct
Phishing is the fraudulent practice of sending emails purporting to be from reputable companies. When it is highly targeted at a specific individual or organization (like impersonating the CEO to trick a specific finance employee), it is known as spear-phishing (or 'whaling' if targeting a senior executive).

Common mistakes

Confusing phishing with ransomware. Ransomware locks systems; phishing tricks users into handing over data or money voluntarily.

Practice the full ACCA BT — Business & Technology Practice Exam 2

52 questions · hints · full answers · grading

More questions from this exam