
EC-CouncilDigital Forensics Essentials
Domain 6Objective 3
Email Crime Investigation DFE Practice Questions (Page 7)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
44questions here
9free pages
7concepts
Questions 31–35
- 31
A user reports receiving a phishing email that appears to come from the company's CEO. The email's Reply-To address is an external Gmail account, and the Received headers show the message originated from an IP address in a foreign country. The user wants to know if the email was truly sent by the CEO. What is the most reliable way to determine whether the email was spoofed?
Select an answer first - 32
A forensic examiner is investigating a case involving emails from a mobile device. The device uses a cloud-based email service. The examiner needs to recover deleted emails that were synced to the device. What is the most significant challenge?
Select an answer first - 33
You are investigating a case where a suspect used a webmail service to send threatening emails. The suspect has since deleted the emails from their account. You have a court order for the email provider. What is the best approach to recover the deleted emails?
Select an answer first - 34
An investigator is tracing an email that was sent anonymously. The email headers show a chain of 'Received' headers, but the originating IP address is a public IP that belongs to a VPN provider. What is the most significant challenge in identifying the sender?
Select an answer first - 35
Which email header field is used to trace the path an email took from the sender's mail server to the recipient's mailbox?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.