
EC-CouncilDigital Forensics Essentials
Domain 6Objective 3
Email Crime Investigation DFE Practice Questions (Page 2)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
44questions here
9free pages
7concepts
Questions 6–10
- 6
A company has received a complaint about an employee sending harassing emails to a coworker. The IT team is asked to investigate. What is the first step in the email crime investigation process?
Select an answer first - 7
An analyst is tracing a suspicious email that was sent to multiple employees. The email headers show a 'Received' chain with several hops, but the originating IP address is a private IP (e.g., 192.168.x.x). What does this indicate, and what should the analyst do next?
Select an answer first - 8
You are investigating a harassment complaint involving emails sent from a company account. The mailbox is on a corporate Exchange server. You need to preserve evidence for potential litigation. Which action best preserves the forensic integrity of the email evidence?
Select an answer first - 9
A user receives an email that appears to be from a colleague, but the email's 'Reply-To' address is different from the colleague's known address. The email asks the user to click a link. What is the most likely explanation?
Select an answer first - 10
An organization is facing a lawsuit and must preserve email evidence. The IT team is asked to place a legal hold on a specific user's mailbox. The mailbox is hosted in Microsoft 365. What is the most appropriate action to ensure the emails are preserved?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.