CAS-005 · Question #26
A security analyst needs to ensure email domains that send phishing attempts without previous communications are not delivered to mailboxes. The following email headers are being reviewed: Which of…
The correct answer is C. Quarantine all messages with sales-mail.com in the email header. The email with the "sales-mail.com" domain stands out, as it is a suspicious "reply-to" domain that is different from the sending domain. This inconsistency could be indicative of phishing attempts. Quarantining these emails ensures they are reviewed before being delivered…
Question
A security analyst needs to ensure email domains that send phishing attempts without previous communications are not delivered to mailboxes. The following email headers are being reviewed:
Which of the following is the best action for the security analyst to take?
Exhibits
Options
- ABlock messages from hr-saas.com because it is not a recognized domain
- BReroute all messages with unusual security warning notices to the IT administrator
- CQuarantine all messages with sales-mail.com in the email header
- DBlock vendor com for repeated attempts to send suspicious messages
How the community answered
(53 responses)- A4% (2)
- B15% (8)
- C74% (39)
- D8% (4)
Explanation
The email with the "sales-mail.com" domain stands out, as it is a suspicious "reply-to" domain that is different from the sending domain. This inconsistency could be indicative of phishing attempts. Quarantining these emails ensures they are reviewed before being delivered, helping mitigate potential risks without blocking legitimate communications from the recognized sales
Community Discussion
No community discussion yet for this question.

