
EC-CouncilDigital Forensics Essentials
Domain 6Objective 5
Business Email Compromise (BEC) Investigations DFE Practice Questions (Page 6)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
54questions here
11free pages
10concepts
Questions 26–30
- 26
You are investigating a BEC email that claims to be from a supplier. The email's domain is 'supplier-corp.com', but the legitimate supplier uses 'suppliercorp.com'. Which verification step would most quickly reveal this discrepancy?
Select an answer first - 27
Which of the following is a safe method to inspect a URL embedded in a BEC email?
Select an answer first - 28
Which of the following is a primary digital evidence source in a BEC investigation?
Select an answer first - 29
A company discovered a BEC attack where an attacker impersonated the CEO and requested a wire transfer of $50,000 to a new vendor. The finance team executed the transfer. The investigator has access to email logs, the CEO's mailbox, the finance team's mailbox, and the bank's transaction records. The investigator needs to determine the exact timeline of the attack. What is the most effective approach?
Select an answer first - 30
A BEC email contains a URL that appears to be a shortened link (e.g., bit.ly/xyz). The email claims to be from a bank and asks the recipient to verify their account. What is the most effective way to analyze this link?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.