
EC-CouncilDigital Forensics Essentials
Domain 6Objective 4
Email Header Analysis and Authentication DFE Practice Questions (Page 8)
Part of the Dark Web and Email Forensics domain, which makes up ~16% of our current practice bank.
40questions here
8free pages
8concepts
Questions 36–40
- 36
You are analyzing an email header that contains the following Authentication-Results line: Authentication-Results: mx.example.com; spf=pass smtp.mailfrom=example.com; dkim=pass header.d=example.com; dmarc=pass (p=reject, sp=reject) header.from=example.com Which conclusion is correct?
Select an answer first - 37
You are investigating an email that has a valid DKIM signature, but the body of the email appears to have been altered after it was sent. What is the most likely explanation?
Select an answer first - 38
Which field within a Received header typically contains the IP address of the server that sent the message to the receiving server?
Select an answer first - 39
A company's domain has the following DMARC record: v=DMARC1; p=reject; rua=mailto:dmarc@example.com An email is sent from a server not listed in the SPF record, and the DKIM signature is invalid. What will a receiving mail server that supports DMARC do with this email?
Select an answer first - 40
You are analyzing an email that appears to be from a bank. The Received headers show a path that goes through a server in a foreign country, but the bank's legitimate mail servers are in your country. What is the most likely conclusion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to DFE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DFE” is a trademark of its owner, used for identification only.