Held Hostage at Harvest - Course Manual
Rating
0
0
There are no comments for now.
Join this Course
to be the first to leave a comment.
1.
A hub agent receives an email with an attachment named 'BG_Sync_Update.exe' from an address that looks like BG IT. The agent is in the middle of harvest data entry and the email says the file must be installed before systems sync tonight. Which action best describes what the agent should do?
Open the attachment quickly — harvest data sync cannot be delayed.
Forward the email to a colleague to confirm before opening it.
Do not open the attachment. Check the full sender address. Report the email to [email protected].
Save the attachment to the desktop and open it after harvest data entry is complete.
2.
An employee's laptop begins showing a message saying all files are locked and a payment is required to restore access. She has not opened any suspicious files today that she can remember. Which of the following best explains what most likely happened, and what she should do right now?
This is a system error. Restart the laptop to clear the message.
The ransomware may have been installed days ago and is only now activating. She should disconnect from the network immediately, not restart, and call Tobi Adeyemo on Zoho Cliq.
Pay the ransom immediately to recover access before harvest data is lost.
Report it to her line manager at the end of the day and monitor for further messages.
3.
A staff member asks: 'If ransomware locks all our files, can IT just unlock them?' Which of the following is the most accurate response?
Yes — IT has a master key that can unlock any encrypted file within the hour.
Yes — as long as the staff member restarts the infected device quickly, IT can recover everything.
No — IT cannot recover encrypted files without either the attacker's decryption key or a clean, tested backup taken before the infection.
No — but paying the ransom is always the fastest way to recover files.
4.
A field agent finds a USB memory stick near a hub entrance. It has a BG logo sticker on it. He assumes someone from the office dropped it and plugs it into his work device to check if it belongs to a colleague. What risk has he introduced, and what should he have done?
No risk — the BG logo confirms it is a legitimate BG device. This was the right action.
Low risk — USB devices cannot install ransomware automatically on modern devices.
High risk — infected USB devices can install ransomware silently on connection. He should have handed it to IT Security without plugging it in.
Medium risk — he should have scanned it with antivirus software first before plugging in.
5.
A staff member receives an email appearing to come from the Head of Finance requesting an urgent payment to a vendor before close of business. The email also says to keep the payment confidential until it clears. The email address looks legitimate. Which of the following best identifies what is happening and why?
This is a legitimate payment instruction — the Head of Finance's address is verified.
This contains two of the three BEC signals: urgency and confidentiality. The correct response is to call the Head of Finance directly on a known BG number before taking any action.
Forward the email to a colleague in Finance to process on your behalf.
Reply to the email asking for a purchase order number to verify the request.
6.
Which combination of signals in an email should trigger the highest level of caution and immediate verification before any action is taken?
A long email with a formal tone and correct BG email signature.
An email marked urgent with a request to update a vendor's payment account details, sent with an instruction not to discuss it with the finance team.
An email from HR about a payroll update, received on the last working day of the month.
A forwarded email from a colleague confirming a payment has already been processed.
7.
A procurement officer receives a BEC email and, before verifying it, emails back to ask for confirmation. The attacker replies confirming the payment. The officer then processes the transfer. What went wrong, and what should have happened?
Nothing went wrong — the officer sought confirmation before acting.
The officer verified through the wrong channel. Replying to the email confirmed the instruction with the attacker, not the real sender. The officer should have called the apparent sender on their known BG phone number.
The officer should have copied the IT team on the reply before acting.
The officer should have waited 24 hours before processing any large payment.
8.
A hub supervisor notices that during October and November, his team is most likely to receive unusual emails with attachments relating to harvest data. He asks why this timing is not coincidental. Which of the following best explains the pattern?
Email servers are busier in October and November, causing more spam to get through.
BG's IT systems are updated in October, making devices temporarily more vulnerable.
Attackers time ransomware campaigns to coincide with BG's harvest season because staff are under maximum operational pressure and are less likely to pause and verify before opening attachments.
The rainy season affects internet connectivity, which causes more phishing emails to arrive.
9.
A staff member suspects she may have clicked a link in a suspicious email earlier in the day. Her device seems to be working normally. She is not sure whether anything has actually happened. What should she do?
Monitor the device for a few days and report only if something unusual happens.
Run an antivirus scan and if it finds nothing, assume the device is clean.
Report to [email protected] immediately and message Tobi Adeyemo on Zoho Cliq, even if the device appears normal. Include the time she clicked and what the link looked like.
Change her BG portal password and consider the matter resolved.
10.
During disbursement season, a Finance Associate receives two emails within an hour. The first appears to be from the CEO asking for an urgent vendor account change — marked confidential. The second appears to be from BG IT with an attachment described as a 'disbursement reconciliation tool.' What is the correct response to both?
Process the vendor account change and open the tool — both are from senior BG contacts and disbursement season makes both plausible.
For the first email: call the CEO on their known BG number before taking any action. For the second: do not open the attachment. Report both emails to [email protected].
Forward both emails to the Head of Finance and let them decide.
Open the IT attachment first to check if it is legitimate, then decide on the vendor email.