▸case-20 During a post-incident review of a high-profile user account, what specific mailbox permission change must be audited to ensure an attacker has not retained access to read or send messages? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 When analyzing email headers for social engineering attacks that lack links or executable payloads, which specific header field pair should be evaluated for domain inconsistency during initial gateway inspection? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 An organization is structuring its overall BEC defensive program into four core phases: behavioral analytics, financial controls, email rules, and account compromise monitoring. What is the correct chronological sequence of these four steps in the standard operational workflow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 An attacker sends an email to the HR department posing as the Chief Human Resources Officer, demanding employee W-2 forms and tax records immediately. Standard security filters found no attached files or links. Under the FBI IC3 classification schema, what category of BEC attack is this? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 An executive assistant receives an email supposedly from the company CEO asking them to immediately purchase financial tokens for an upcoming staff event. What non-standard payment instrument request serves as an immediate red flag? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 A finance director receives a direct email displaying the Chief Executive Officer's name, requesting an immediate wire transfer to complete a time-sensitive acquisition. Under FBI IC3 standards, what specific BEC classification describes this incident? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 A threat actor gains unauthorized access to a legitimate employee's corporate mailbox and sends fraudulent wire payment requests to external business partners. Under the FBI IC3 BEC classification framework, what is the exact category for this scenario? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 A network administrator needs to generate a DNS TXT record for email authentication authorizing Google Workspace (`_spf.google.com`) with a soft fail policy. Provide the exact syntactical format for this DNS record. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 A security operations team is configuring an AI email security platform to detect subtle impersonation. What primary baseline metric must be established during Step 2 behavioral analytics? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 A senior manager receives an urgent message claiming to be from external legal counsel regarding a confidential acquisition, instructing them to immediately wire legal retainer funds without notifying colleagues. Under FBI IC3 standards, what specific BEC category applies? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 During an investigation into a compromised mailbox, a security analyst suspects the attacker is suppressing incoming security warnings. What specific client-side rule mechanism should be audited in Step 4 of the investigation? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 A compliance officer is reviewing financial sector guidance regarding illicit financial flows from corporate email scams. Which US financial intelligence agency publishes official advisories on BEC patterns for financial institutions? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 An email arrives appearing to come from an established enterprise vendor, requesting that all future payments for outstanding invoices be remitted to a newly updated bank routing number. No malicious attachments are detected. According to FBI IC3 classification guidelines, which attack category does this describe? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 A corporate treasury department is revising financial authorization policies to prevent unauthorized fund transfers triggered by executive impersonation. What administrative financial control rule should be required for transfers exceeding a designated dollar limit? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 An employee receives an email containing a password-protected ZIP file housing `invoice_88201.exe`. The SOC team needs to safely observe the program's runtime process injection and dynamic DLL loadings. What technical process should be performed on this binary file? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 A security log monitor triggers an alert when a user authenticates to cloud email from Chicago and then authenticates from Tokyo 30 minutes later. What log anomaly descriptor defines this indicator in email compromise monitoring? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 A SOC engineer is setting up mail flow rules in Exchange Online to combat executive impersonation. What specific message attribute comparison should be configured as the primary Step 1 rule for detecting external emails spoofing executives? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 Following a major wire transfer fraud incident involving executive impersonation, which federal reporting portal and crime advisory center should the incident response team file a formal report with? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 A threat hunter is creating SIEM alerts for email account takeover behavior in Microsoft 365. Which specific MITRE ATT&CK sub-technique ID corresponds to auto-forwarding rule creation used to intercept messages? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 An accounting clerk receives an email requesting a change to direct deposit banking details for a long-time contractor. The message passes SPF and DKIM checks. What mandatory operational financial control step must be performed before updating the payment system? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 A detection engineer is writing keyword-matching patterns for email security rules. What specific category of social engineering language flags potential BEC risk when combined with fund transfer terminology? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 An inbound email arrives in a finance manager's inbox from an external domain requesting payment approval. What interaction analytics metric evaluated by behavioral email security tools flags this email as suspicious? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 A network security administrator needs to block outbound SMB traffic across the corporate perimeter firewall on port 445 to mitigate network worm proliferation. What firewall rule action and port parameter should be defined? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |