
EC-CouncilDigital Forensics Essentials
Domain 6Objective 3
Email Crime Investigation DFE Practice Questions (Page 1)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
44questions here
9free pages
7concepts
Questions 1–5
- 1
An email with a spoofed sender address has been received. You need to trace the actual originating IP. Which header field is most reliable for this purpose?
Select an answer first - 2
A security team is investigating a business email compromise (BEC) attack. The attacker spoofed the CEO's email address and sent a wire transfer request. The email passed SPF and DKIM checks. What is the most likely reason the email passed these checks?
Select an answer first - 3
An organization is investigating a case of internal email harassment. The investigator plans to collect emails from the accused employee's mailbox. Which legal and ethical principle is most important to consider before proceeding?
Select an answer first - 4
You are investigating a case involving emails stored in a Microsoft Exchange database. The suspect has deleted some emails, and you need to recover them. Which tool is specifically designed to parse Exchange databases and recover deleted items?
Select an answer first - 5
A forensic examiner is analyzing a suspect's email database from a desktop client like Microsoft Outlook. The examiner needs to recover emails that were deleted but may still exist in the mailbox. Which file should the examiner prioritize for analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.