
EC-CouncilCertified Security Specialist
Domain 6Objective 6
Investigating Email Crimes ECSS Practice Questions (Page 1)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
44questions here
9free pages
8concepts
Questions 1–5
- 1
You are tracing a phishing email. The Received headers show the message passed through three servers. The last Received header (bottom) shows an IP address 203.0.113.9. You want to identify the actual sender. What is the most reliable method?
Select an answer first - 2
During an email crime investigation, you find an attachment named 'invoice.pdf' in a suspect's Sent Items folder. The file's hash matches a known malware sample. What is the most appropriate next step?
Select an answer first - 3
An investigator is preparing a report for a case involving fraudulent emails. The report must be admissible in court. Which element is MOST critical to include?
Select an answer first - 4
During an email crime investigation, you find an email with an attachment that contains a hidden macro. You need to analyze the attachment without compromising the evidence. Select all that apply.
Select an answer first - 5
An investigator is analyzing a suspicious email. The headers show: Received: from mail.attacker.com (mail.attacker.com [192.0.2.1]) by mx.victim.com; Received: from [10.0.0.5] by mail.attacker.com; and the From header is 'ceo@victim.com'. The SPF check for victim.com fails. The investigator wants to trace the true origin. What is the most significant obstacle?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.