
EC-CouncilCertified Security Specialist
Domain 6Objective 6
Investigating Email Crimes ECSS Practice Questions (Page 2)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
44questions here
9free pages
8concepts
Questions 6–10
- 6
An investigator is analyzing an email that contains an attachment with a suspicious macro. The investigator needs to extract the macro code for analysis without executing it. Which method is the most appropriate?
Select an answer first - 7
An investigator is collecting email evidence from a suspect's computer. The computer is running and the email client is open. What is the first step the investigator should take to preserve the evidence?
Select an answer first - 8
You are collecting email evidence from an employee's Outlook mailbox. The employee is under investigation for leaking confidential data. What is the best way to preserve the mailbox?
Select an answer first - 9
When tracing an email, which server logs are most valuable for correlating the message with a specific user or session?
Select an answer first - 10
An investigator has collected a suspect email as an .eml file from a user's computer. The investigator needs to ensure the evidence is preserved and can be verified later. Which action is the most appropriate for preserving the integrity of the email evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.