
EC-CouncilCertified Security Specialist
Domain 6Objective 6
Investigating Email Crimes ECSS Practice Questions (Page 6)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
44questions here
9free pages
8concepts
Questions 26–30
- 26
Which of the following is the first step in the investigative process for an email crime?
Select an answer first - 27
An investigator is examining an email that claims to be from a bank. The email's 'From' header shows the bank's domain, but the 'Received-SPF' header shows 'fail'. The investigator also notices that the 'Authentication-Results' header indicates 'dkim=fail'. What is the most likely conclusion about this email?
Select an answer first - 28
During an email crime investigation, the investigator has a suspect email with an attachment. The investigator needs to extract evidence from the attachment without altering it. Which approach is the most appropriate?
Select an answer first - 29
You are tracing a threatening email. The Received headers show the message originated from an IP address that belongs to a public Wi-Fi hotspot. The hotspot does not keep logs. What is the best alternative to identify the sender?
Select an answer first - 30
During email evidence analysis, which of the following is considered metadata that can provide valuable investigative information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.