nerdexam
CompTIA

CAS-005 · Question #26

A security analyst needs to ensure email domains that send phishing attempts without previous communications are not delivered to mailboxes. The following email headers are being reviewed: Which of…

The correct answer is C. Quarantine all messages with sales-mail.com in the email header. The email with the "sales-mail.com" domain stands out, as it is a suspicious "reply-to" domain that is different from the sending domain. This inconsistency could be indicative of phishing attempts. Quarantining these emails ensures they are reviewed before being delivered…

Submitted by tunde_lagos· Mar 6, 2026Security Operations

Question

A security analyst needs to ensure email domains that send phishing attempts without previous communications are not delivered to mailboxes. The following email headers are being reviewed:

Which of the following is the best action for the security analyst to take?

Exhibits

CAS-005 question #26 exhibit 1
CAS-005 question #26 exhibit 2

Options

  • ABlock messages from hr-saas.com because it is not a recognized domain
  • BReroute all messages with unusual security warning notices to the IT administrator
  • CQuarantine all messages with sales-mail.com in the email header
  • DBlock vendor com for repeated attempts to send suspicious messages

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    15% (8)
  • C
    74% (39)
  • D
    8% (4)

Explanation

The email with the "sales-mail.com" domain stands out, as it is a suspicious "reply-to" domain that is different from the sending domain. This inconsistency could be indicative of phishing attempts. Quarantining these emails ensures they are reviewed before being delivered, helping mitigate potential risks without blocking legitimate communications from the recognized sales

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice