nerdexam
CompTIA

CAS-005 · Question #163

Incident responders determine that a company email server was the first compromised machine in an attack. The server was infected by malware. The following are abbreviated headers from three emails…

The correct answer is B. The DMARC security check failed. DMARC failing indicates that the email's sender could not be properly authenticated, making it a likely vector for malware delivery via a spoofed sender.

Submitted by tunde_lagos· Mar 6, 2026Security Operations

Question

Incident responders determine that a company email server was the first compromised machine in an attack. The server was infected by malware. The following are abbreviated headers from three emails that the incident responders could not confidently determine to be safe:

Which of the following is the most likely reason the malware was delivered?

Exhibits

CAS-005 question #163 exhibit 1
CAS-005 question #163 exhibit 2

Options

  • AAn attachment scan could not be completed.
  • BThe DMARC security check failed.
  • CRepeated emails were sent from the same address.
  • DThe SPF check failed.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    80% (16)
  • C
    10% (2)
  • D
    5% (1)

Why each option

DMARC failing indicates that the email's sender could not be properly authenticated, making it a likely vector for malware delivery via a spoofed sender.

AAn attachment scan could not be completed.

An attachment scan failure would prevent the scan itself, but the question implies a broader email security check failure related to headers.

BThe DMARC security check failed.Correct

A failed DMARC security check means the email's sender domain could not be authenticated according to its published policy, often indicating a spoofed email that could contain malware and bypass standard security controls.

CRepeated emails were sent from the same address.

Repeated emails from the same address do not inherently indicate malware delivery, unless they are part of a phishing campaign that DMARC would ideally catch.

DThe SPF check failed.

While SPF failing is a component of DMARC failure, DMARC encompasses the overall policy and action, making it a more comprehensive reason for a malicious email bypassing checks.

Concept tested: Email authentication DMARC failure

Source: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/email-authentication-dmarc-overview?view=o365-worldwide

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice