A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:
SPF = PASS
DKIM = FAIL
DMARC = FAIL
Which of the following did the analyst most likely discover?
Comprehensive and Detailed Step-by-Step The SPF = PASS result confirms the email came from an authorized server, but DKIM = FAIL indicates the message was not properly signed with the expected DomainKeys Identified Mail (DKIM) signature. DMARC = FAIL suggests that because DKIM failed, the overall email authentication failed. This scenario is consistent with a legitimate server sending an unsigned email.
CompTIA CySA+ All-in-One Guide (Chapter 5: Email Analysis)
CompTIA CySA+ Practice Tests (Domain 1.3 Email Authentication)
Jettie
2 months agoHerman
2 months agoElly
2 months agoCarmen
3 months agoLyla
3 months agoAngella
3 months agoMabelle
3 months agoElza
4 months agoMyra
4 months agoTorie
4 months agoToshia
4 months agoJaleesa
4 months agoGladys
5 months agoMartina
5 months agoBobbye
10 months agoKerry
9 months agoNguyet
9 months agoGarry
10 months agoAdell
10 months agoLeonida
10 months agoChaya
9 months agoQuiana
10 months agoLazaro
10 months agoTracey
10 months agoLauran
10 months agoMarva
10 months agoPearline
11 months agoTashia
11 months agoRosina
9 months agoChaya
10 months agoDahlia
10 months agoJamal
10 months agoDevora
11 months agoLavina
11 months ago