nerdexam
GIAC

GSLC · Question #184

Your Company is receiving false and abusive e-mails from the e-mail address of your partner company. When you complain, the partner company tells you that they have never sent any such e-mails…

The correct answer is C. Spoofing. Email spoofing involves forging the sender address on messages to make them appear to originate from a legitimate or trusted source.

Security Operations & Incident Response Leadership

Question

Your Company is receiving false and abusive e-mails from the e-mail address of your partner company. When you complain, the partner company tells you that they have never sent any such e-mails. Which of the following types of cyber crimes involves this form of network attack?

Options

  • ACyber squatting
  • BCyber Stalking
  • CSpoofing
  • DMan-in-the-middle attack

How the community answered

(62 responses)
  • A
    6% (4)
  • B
    2% (1)
  • C
    87% (54)
  • D
    5% (3)

Why each option

Email spoofing involves forging the sender address on messages to make them appear to originate from a legitimate or trusted source.

ACyber squatting

Cyber squatting is the bad-faith registration of domain names resembling trademarks or brand names to profit from them, which is unrelated to forging the sender address of an email message.

BCyber Stalking

Cyber stalking refers to the use of digital means to repeatedly harass or threaten a specific individual, which describes intent and behavior rather than the technical act of forging a sender identity.

CSpoofingCorrect

Spoofing is the technique of falsifying identifying information - in this case the email 'From' header - so that messages appear to come from a party that did not actually send them. The SMTP protocol historically lacks built-in sender verification, making email address forgery straightforward for attackers. The partner company's denial confirms the address was forged rather than their account being compromised and used to send mail.

DMan-in-the-middle attack

A man-in-the-middle attack involves an adversary secretly intercepting and potentially altering communications between two parties in real time, which is a different attack vector from simply forging an email's originating address.

Concept tested: Email spoofing and sender identity forgery

Source: https://learn.microsoft.com/en-us/defender-office-365/anti-spoofing-protection

Topics

#email spoofing#identity forgery#cyber crime#network attacks

Community Discussion

No community discussion yet for this question.

Full GSLC Practice