Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilDigital Forensics Essentials

Domain 6Objective 4

Email Header Analysis and Authentication DFE Practice Questions (Page 6)

Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.

40questions here
8free pages
8concepts

Questions 26–30

  1. 26application · medium

    An analyst is reviewing headers of an email that claims to be from the CEO. The Received chain shows the message entered the company's mail server from an IP in a foreign country, but the From header displays the CEO's address. The Message-ID was generated by the foreign mail server. Which finding most strongly indicates header forgery?

    Select an answer first
  2. 27foundation · easy

    Which email header field is used to store a unique identifier for the message, which can help correlate related messages and detect certain types of forgery?

    Select an answer first
  3. 28foundation · easy

    What is the purpose of DMARC alignment?

    Select an answer first
  4. 29foundation · easy

    An email is received with an SPF result of 'pass'. What does this indicate?

    Select an answer first
  5. 30expert · medium

    A security team is implementing email authentication for a domain that sends a high volume of legitimate email through a third-party marketing service. The team wants to ensure that emails from the marketing service are authenticated, but they also want to avoid rejecting legitimate emails if the marketing service occasionally changes its sending IPs. Which approach best balances security and deliverability?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.