nerdexam
CompTIA

220-1002 · Question #511

A user is receiving a large number of suspicious emails, many of which are automated emails that state the recipient cannot be found. Which of the following is the MOST likely cause of the issue?

The correct answer is B. The user's email was hijacked. When a user's email account is hijacked (compromised), attackers use it to send mass spam or phishing emails to thousands of addresses. Many of those addresses are invalid or no longer active, causing mail servers to send Non-Delivery Reports (NDRs) - also called bounce-back…

Networking

Question

A user is receiving a large number of suspicious emails, many of which are automated emails that state the recipient cannot be found. Which of the following is the MOST likely cause of the issue?

Options

  • AAn invalid certificate is on the mail server
  • BThe user's email was hijacked
  • CThe user's address book was corrupted
  • DThe user's system time is different from the mail server.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    77% (23)
  • C
    13% (4)
  • D
    7% (2)

Explanation

When a user's email account is hijacked (compromised), attackers use it to send mass spam or phishing emails to thousands of addresses. Many of those addresses are invalid or no longer active, causing mail servers to send Non-Delivery Reports (NDRs) - also called bounce-back messages or mailer-daemon emails - back to the originating address (the victim's email). This flood of automated 'recipient not found' messages in the user's inbox is a strong indicator their account has been compromised and is being used to send spam. An invalid certificate (A) would cause connection errors, not bounce messages. A corrupted address book (C) might cause send failures but not the described volume of automated responses. A time mismatch (D) could cause authentication issues but not mass bounce-backs. The combination of suspicious outgoing activity and bounce-back NDRs is the classic symptom of a hijacked email account.

Topics

#email hijacking#account compromise#spam bounce messages#phishing

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice