โ† All CFE Flashcard Decks

Certified Fraud Examiner Digital Forensics and Technology Fraud Flashcards

6 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Certified Fraud Examiner Digital Forensics and Technology Fraud flashcards as text
  1. Which type of computer fraud involves an employee inserting unauthorized code that skims small amounts from many accounts into a single account?

    Answer: Round-down scheme

    A round-down scheme (also called a salami attack) involves programming a system to round down fractions of cents from many transactions and accumulate those fractions in a single account.

  2. Which term describes malware that encrypts a victim's files and demands payment for the decryption key?

    Answer: Ransomware

    Ransomware is malicious software that encrypts the victim's data and demands a ransom, typically in cryptocurrency, in exchange for the decryption key.

  3. In a Business Email Compromise (BEC) scheme, the fraudster typically impersonates which individual to authorize fraudulent wire transfers?

    Answer: A senior executive such as the CEO or CFO

    BEC schemes most commonly involve impersonating a senior executive (CEO or CFO) to pressure finance employees into authorizing fraudulent wire transfers.

  4. Which technique do fraudsters use to make an email appear to come from a legitimate source by altering the 'From' field?

    Answer: Email spoofing

    Email spoofing involves forging the sender's address in the email header to make the message appear to originate from a trusted or legitimate source.

  5. Which type of fraud involves creating fictitious identities by combining real and fabricated personal information to obtain credit?

    Answer: Synthetic identity fraud

    Synthetic identity fraud uses a blend of real information (often a Social Security number) combined with fabricated details to create a new fraudulent identity.

  6. What is the primary purpose of a honeypot in a fraud detection context?

    Answer: To lure and detect unauthorized users or fraudsters accessing systems

    A honeypot is a decoy system or data set designed to attract and identify unauthorized access attempts, helping organizations detect insider threats or external attackers.