
EC-CouncilDigital Forensics Essentials
Domain 6Objective 3
Email Crime Investigation DFE Practice Questions (Page 5)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
44questions here
9free pages
7concepts
Questions 21–25
- 21
A forensic examiner needs to recover deleted emails from a Microsoft Exchange server as part of an investigation. The emails were deleted by the user and have already been purged from the 'Deleted Items' folder. What is the most appropriate next step?
Select an answer first - 22
An HR manager suspects an employee is using their corporate email to leak confidential data. The manager asks you, the IT security analyst, to 'just take a quick look' at the employee's mailbox to confirm the suspicion before involving legal. What should you do?
Select an answer first - 23
A user reports receiving a threatening email that appears to come from the CEO's address. You examine the full headers and see that the 'Return-Path' domain is 'example.net' while the 'From' header shows '@company.com'. The 'Received' chain shows the message entered the company's mail server from an IP address in a foreign country. What is the most reliable conclusion from these header observations?
Select an answer first - 24
What is the primary function of an email forensic tool when examining a suspect's email database?
Select an answer first - 25
Which part of an email header is most useful for identifying the IP address of the originating mail server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.