
EC-CouncilCertified Security Specialist
Domain 6Objective 6
Investigating Email Crimes ECSS Practice Questions (Page 8)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
44questions here
9free pages
8concepts
Questions 36–40
- 36
What is the purpose of hashing email evidence during preservation?
Select an answer first - 37
A company has received a threatening email. The email headers show a 'Received' chain that includes a server in a foreign country, but the 'Received-SPF' header shows 'pass' for the company's own domain. The investigator suspects the email was sent through a compromised internal account. Which action is most likely to confirm this suspicion?
Select an answer first - 38
Which of the following is the recommended method for preserving email evidence from a local email client?
Select an answer first - 39
What is the primary goal of the investigative process when handling an email-related offense?
Select an answer first - 40
Which part of an email header provides the routing path of the message from the sender's mail server to the recipient's mail server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.