
EC-CouncilCertified Security Specialist
Domain 6Objective 6
Investigating Email Crimes ECSS Practice Questions (Page 9)
Part of the Digital Forensics Investigations domain, which makes up ~20% of our current practice bank.
44questions here
9free pages
8concepts
Questions 41–44
- 41
An investigator has collected a mailbox image and computed its SHA-256 hash. Later, the defense attorney claims the evidence was tampered with. What is the best way to refute this claim?
Select an answer first - 42
A company is investigating a phishing email that bypassed its email gateway. The security team has access to the email headers and the company's mail server logs. The team wants to trace the email back to the original sender's IP address. Which combination of data is most useful for this purpose?
Select an answer first - 43
What is the primary purpose of documenting findings in an email crime investigation?
Select an answer first - 44
An email investigator is examining a phishing email and wants to determine if the email was sent from a legitimate source or if it was spoofed. The investigator has access to the full email headers. Which header field is most useful for verifying the sender's identity?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECSS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.