
EC-CouncilCertified Security Specialist
Domain 6Objective 6
Investigating Email Crimes ECSS Practice Questions (Page 7)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
44questions here
9free pages
8concepts
Questions 31–35
- 31
Which of the following is a key element of a well-written email crime investigation report?
Select an answer first - 32
In an email header, which field typically contains the email address of the sender as displayed to the recipient?
Select an answer first - 33
An investigator is preparing a report for an email crime investigation. The report will be reviewed by a non-technical legal team. The investigator has collected email headers, server logs, and forensic images. What is the most effective way to present the technical evidence in the report?
Select an answer first - 34
During analysis of an email, you notice the 'Received' timestamp is 30 minutes before the 'Date' header. What does this indicate?
Select an answer first - 35
An investigator has collected email evidence from a suspect's computer. The evidence includes an email client's mailbox file and several related files. The investigator needs to preserve the evidence in a way that allows for later analysis without altering the original. Which approach is the most forensically sound?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.