
GIAC Certified Forensic Examiner
Domain 6Objective 3
Email Analysis GCFE Practice Questions (Page 4)
Part of the User and Cloud Artifacts domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
8concepts
Questions 16–20
- 16
Which type of email attachment is considered especially dangerous because it can contain macros that execute when the document is opened?
Select an answer first - 17
When analyzing an email for malicious indicators, which element should be examined to identify the actual destination of a link without clicking it?
Select an answer first - 18
Which email authentication mechanism uses a cryptographic signature stored in the email header to verify that the message was not altered in transit and that it originated from the claimed domain?
Select an answer first - 19
A user reports receiving a phishing email that appears to come from the company CEO. The email's From header shows the CEO's display name and email address. You examine the full headers and see that the Return-Path is attacker@example.net, the SPF result is 'fail', and the DKIM signature is missing. However, the DMARC policy in the company's DNS is p=none. What is the most accurate conclusion about this email?
Select an answer first - 20
You are analyzing an email file and need to determine the time zone in which the email was sent. Which header field would provide this information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.