Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank's staff receive emails appearing to come from the CEO, urging an urgent wire transfer to a new supplier account and asking for secrecy. No malware is attached and no technical vulnerability is exploited. Which control would be most directly effective against this threat?

Out-of-band verification combined with dual authorization is most effective. The scenario is social engineering that exploits trust without malware or technical vulnerabilities, so process controls that independently confirm payment requests directly interrupt the fraud, whereas firewalls, encryption at rest and segmentation do not.

  1. AStronger perimeter firewall rules on inbound traffic
  2. BOut-of-band verification and dual authorization for payment changesCorrect
  3. CEncryption of data at rest on all servers
  4. DNetwork segmentation of the core banking system

Explanation

This is social engineering (business email compromise) that exploits human trust, not technical flaws. Call-back verification through a known channel and dual approval break the fraud chain. Firewalls, encryption at rest and segmentation address technical intrusion and do not stop an employee being persuaded to send a payment.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions