Certified Fraud Examiner Digital Forensics and Technology Fraud Flashcards
6 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Certified Fraud Examiner Digital Forensics and Technology Fraud flashcards as text
Which type of computer fraud involves an employee inserting unauthorized code that skims small amounts from many accounts into a single account?
Answer: Round-down scheme
A round-down scheme (also called a salami attack) involves programming a system to round down fractions of cents from many transactions and accumulate those fractions in a single account.
Which term describes malware that encrypts a victim's files and demands payment for the decryption key?
Answer: Ransomware
Ransomware is malicious software that encrypts the victim's data and demands a ransom, typically in cryptocurrency, in exchange for the decryption key.
In a Business Email Compromise (BEC) scheme, the fraudster typically impersonates which individual to authorize fraudulent wire transfers?
Answer: A senior executive such as the CEO or CFO
BEC schemes most commonly involve impersonating a senior executive (CEO or CFO) to pressure finance employees into authorizing fraudulent wire transfers.
Which technique do fraudsters use to make an email appear to come from a legitimate source by altering the 'From' field?
Answer: Email spoofing
Email spoofing involves forging the sender's address in the email header to make the message appear to originate from a trusted or legitimate source.
Which type of fraud involves creating fictitious identities by combining real and fabricated personal information to obtain credit?
Answer: Synthetic identity fraud
Synthetic identity fraud uses a blend of real information (often a Social Security number) combined with fabricated details to create a new fraudulent identity.
What is the primary purpose of a honeypot in a fraud detection context?
Answer: To lure and detect unauthorized users or fraudsters accessing systems
A honeypot is a decoy system or data set designed to attract and identify unauthorized access attempts, helping organizations detect insider threats or external attackers.