
EC-CouncilDigital Forensics Essentials
Domain 6Objective 4
Email Header Analysis and Authentication DFE Practice Questions (Page 1)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
40questions here
8free pages
8concepts
Questions 1–5
- 1
When tracing the origin of an email, which Received header should be examined first to identify the most recent server that handled the message?
Select an answer first - 2
An analyst is examining an email that appears to be from a colleague. The Received headers show the email was sent from an IP address that is not in the company's known range, but the From header is the colleague's address. The Message-ID is in the format of an external service. Which of the following is the most reliable indicator that the email is spoofed?
Select an answer first - 3
Where does a receiving mail server obtain the public key needed to verify a DKIM signature?
Select an answer first - 4
Which DNS record type is used to publish an SPF policy for a domain?
Select an answer first - 5
You are examining an email with a DKIM signature. The signature is valid, but the 'From' header was not included in the signed headers. What is the implication?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.