FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank's staff receive emails appearing to come from the CEO, urging an urgent wire transfer to a new supplier account and asking for secrecy. No malware is attached and no technical vulnerability is exploited. Which control would be most directly effective against this threat?
Out-of-band verification combined with dual authorization is most effective. The scenario is social engineering that exploits trust without malware or technical vulnerabilities, so process controls that independently confirm payment requests directly interrupt the fraud, whereas firewalls, encryption at rest and segmentation do not.
- AStronger perimeter firewall rules on inbound traffic
- BOut-of-band verification and dual authorization for payment changesCorrect
- CEncryption of data at rest on all servers
- DNetwork segmentation of the core banking system
Explanation
This is social engineering (business email compromise) that exploits human trust, not technical flaws. Call-back verification through a known channel and dual approval break the fraud chain. Firewalls, encryption at rest and segmentation address technical intrusion and do not stop an employee being persuaded to send a payment.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A regional bank's security team observes a group that has quietly maintained access to its payment-switch network for eleven months, exfiltr…
- Which feature of cyber risk most complicates its quantification relative to other operational risk categories?
- A bank estimates that a phishing-led breach occurs with annual frequency 0.4 and an average loss of USD 5 million per event. A proposed cont…
- A bank's security team discovers that attackers entered through a third-party vendor's stolen credentials, then moved across internal system…
- When a bank builds a cyber loss distribution using a loss distribution approach, which statement about combining frequency and severity is m…
- An insider at an investment firm emails a spreadsheet of client portfolios to a personal account, but the spreadsheet remains unchanged and …