Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 6Objective 4

Email Header Analysis and Authentication DFE Practice Questions (Page 1)

Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.

40questions here
8free pages
8concepts

Questions 1–5

  1. 1foundation · easy

    When tracing the origin of an email, which Received header should be examined first to identify the most recent server that handled the message?

    Select an answer first
  2. 2application · medium

    An analyst is examining an email that appears to be from a colleague. The Received headers show the email was sent from an IP address that is not in the company's known range, but the From header is the colleague's address. The Message-ID is in the format of an external service. Which of the following is the most reliable indicator that the email is spoofed?

    Select an answer first
  3. 3foundation · easy

    Where does a receiving mail server obtain the public key needed to verify a DKIM signature?

    Select an answer first
  4. 4foundation · easy

    Which DNS record type is used to publish an SPF policy for a domain?

    Select an answer first
  5. 5application · medium

    You are examining an email with a DKIM signature. The signature is valid, but the 'From' header was not included in the signed headers. What is the implication?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.