A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:
SPF = PASS
DKIM = FAIL
DMARC = FAIL
Which of the following did the analyst most likely discover?
Comprehensive and Detailed Step-by-Step The SPF = PASS result confirms the email came from an authorized server, but DKIM = FAIL indicates the message was not properly signed with the expected DomainKeys Identified Mail (DKIM) signature. DMARC = FAIL suggests that because DKIM failed, the overall email authentication failed. This scenario is consistent with a legitimate server sending an unsigned email.
CompTIA CySA+ All-in-One Guide (Chapter 5: Email Analysis)
CompTIA CySA+ Practice Tests (Domain 1.3 Email Authentication)
Jettie
5 months agoHerman
5 months agoElly
5 months agoCarmen
6 months agoLyla
6 months agoAngella
6 months agoMabelle
6 months agoElza
7 months agoMyra
7 months agoTorie
7 months agoToshia
7 months agoJaleesa
7 months agoGladys
8 months agoMartina
8 months agoBobbye
1 year agoKerry
12 months agoNguyet
1 year agoGarry
1 year agoAdell
1 year agoLeonida
1 year agoChaya
1 year agoQuiana
1 year agoLazaro
1 year agoTracey
1 year agoLauran
1 year agoMarva
1 year agoPearline
1 year agoTashia
1 year agoRosina
1 year agoChaya
1 year agoDahlia
1 year agoJamal
1 year agoDevora
1 year agoLavina
1 year ago