Exam IIA-CIA-Part3 Topic 3 Question 105 Discussion
Actual exam question for IIA's IIA-CIA-Part3 exam
Question #: 105
Topic #: 3
Question #: 105
Topic #: 3
A newly appointed board member received an email that appeared to be from the company's CEO. The email stated:
"Good morning. As you remember, the closure of projects is our top priority. Kindly organize prompt payment of the attached invoice for our new solar energy partners." The board member quickly replied to the email and asked under which project the expense should be accounted. Only then did he realize that the sender 's mail domain was different from the company's. Which of the following cybersecurity risks nearly occurred in the situation described?
"Good morning. As you remember, the closure of projects is our top priority. Kindly organize prompt payment of the attached invoice for our new solar energy partners." The board member quickly replied to the email and asked under which project the expense should be accounted. Only then did he realize that the sender 's mail domain was different from the company's. Which of the following cybersecurity risks nearly occurred in the situation described?
Suggested Answer: D Vote an answer
The described situation is a classic social engineering attack, specifically a phishing or CEO fraud (business email compromise) attempt. Social engineering exploits human psychology rather than technical vulnerabilities. In this case, the attacker attempted to impersonate the CEO and trick the board member into making an unauthorized payment.
(A) Incorrect - A risk of spyware and malware.
Spyware and malware typically involve malicious software installed on a device, which is not the case here.
This attack relied on deception rather than malware to obtain unauthorized funds.
(B) Incorrect - A risk of corporate espionage.
Corporate espionage involves unauthorized data theft, sabotage, or insider threats.
The attacker here attempted financial fraud, not intellectual property theft.
(C) Incorrect - A ransomware attack risk.
Ransomware encrypts files and demands payment for decryption.
There is no mention of system encryption or ransom demands in this case.
(D) Correct - A social engineering risk.
The attacker impersonated the CEO and used urgency to manipulate the board member into processing a fraudulent payment.
This technique is a business email compromise (BEC) scam, a well-known social engineering tactic.
IIA's GTAG (Global Technology Audit Guide) - Cybersecurity Risks and Controls Discusses social engineering and its impact on financial fraud.
NIST Cybersecurity Framework - Social Engineering Threats
Defines social engineering tactics, including email impersonation and phishing.
COBIT Framework - Information Security Governance
Recommends controls to mitigate social engineering risks, such as employee training and email authentication mechanisms.
Analysis of Answer Choices:IIA References and Internal Auditing Standards:
(A) Incorrect - A risk of spyware and malware.
Spyware and malware typically involve malicious software installed on a device, which is not the case here.
This attack relied on deception rather than malware to obtain unauthorized funds.
(B) Incorrect - A risk of corporate espionage.
Corporate espionage involves unauthorized data theft, sabotage, or insider threats.
The attacker here attempted financial fraud, not intellectual property theft.
(C) Incorrect - A ransomware attack risk.
Ransomware encrypts files and demands payment for decryption.
There is no mention of system encryption or ransom demands in this case.
(D) Correct - A social engineering risk.
The attacker impersonated the CEO and used urgency to manipulate the board member into processing a fraudulent payment.
This technique is a business email compromise (BEC) scam, a well-known social engineering tactic.
IIA's GTAG (Global Technology Audit Guide) - Cybersecurity Risks and Controls Discusses social engineering and its impact on financial fraud.
NIST Cybersecurity Framework - Social Engineering Threats
Defines social engineering tactics, including email impersonation and phishing.
COBIT Framework - Information Security Governance
Recommends controls to mitigate social engineering risks, such as employee training and email authentication mechanisms.
Analysis of Answer Choices:IIA References and Internal Auditing Standards:
by Joy at Aug 16, 2026, 12:32 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).