CS0-003 · Question #636
A security analyst is working on a suspicious email forwarded from a user. The email contains an attachment asking the user to open it. Which of the following should the security analyst review to bes
The correct answer is A. DMARC. DMARC results in the email headers show whether the message passed or failed authentication checks such as SPF and DKIM. Reviewing these results helps determine whether the sender was spoofed and provides insight into the likely origin of the attack.
Question
A security analyst is working on a suspicious email forwarded from a user. The email contains an attachment asking the user to open it. Which of the following should the security analyst review to best determine email authentication and its attack origin?
Options
- ADMARC
- BSMTP
- CJoe Sandbox
- DURL rewriting
How the community answered
(45 responses)- A89% (40)
- B2% (1)
- C2% (1)
- D7% (3)
Explanation
DMARC results in the email headers show whether the message passed or failed authentication checks such as SPF and DKIM. Reviewing these results helps determine whether the sender was spoofed and provides insight into the likely origin of the attack.
Topics
Community Discussion
No community discussion yet for this question.