Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 6Objective 4

Email Header Analysis and Authentication DFE Practice Questions (Page 5)

Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.

40questions here
8free pages
8concepts

Questions 21–25

  1. 21foundation · easy

    Which of the following is a common sign of email header forgery?

    Select an answer first
  2. 22foundation · easy

    In a DMARC policy, what does the 'p=quarantine' directive instruct receiving mail servers to do with messages that fail authentication?

    Select an answer first
  3. 23application · medium

    A security analyst is configuring email authentication for a domain. The goal is to prevent attackers from spoofing the domain in phishing emails. Which protocol should be configured to tell receiving mail servers what to do with messages that fail SPF and DKIM checks?

    Select an answer first
  4. 24expert · hard

    You are evaluating an email that has the following Authentication-Results header: Authentication-Results: mx.example.com; spf=pass smtp.mailfrom=example.com; dkim=pass header.d=example.net; dmarc=fail (p=reject) header.from=example.com What is the most likely reason for the DMARC failure?

    Select an answer first
  5. 25application · medium

    An email from your domain shows 'spf=fail' in the Authentication-Results header, but the email was sent from your legitimate mail server. Which of the following is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.