A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:
SPF = PASS
DKIM = FAIL
DMARC = FAIL
Which of the following did the analyst most likely discover?
Comprehensive and Detailed Step-by-Step The SPF = PASS result confirms the email came from an authorized server, but DKIM = FAIL indicates the message was not properly signed with the expected DomainKeys Identified Mail (DKIM) signature. DMARC = FAIL suggests that because DKIM failed, the overall email authentication failed. This scenario is consistent with a legitimate server sending an unsigned email.
CompTIA CySA+ All-in-One Guide (Chapter 5: Email Analysis)
CompTIA CySA+ Practice Tests (Domain 1.3 Email Authentication)
Jettie
9 months agoHerman
9 months agoElly
9 months agoCarmen
9 months agoLyla
10 months agoAngella
10 months agoMabelle
10 months agoElza
10 months agoMyra
11 months agoTorie
11 months agoToshia
11 months agoJaleesa
11 months agoGladys
11 months agoMartina
11 months agoBobbye
1 year agoKerry
1 year agoNguyet
1 year agoGarry
1 year agoAdell
1 year agoLeonida
1 year agoChaya
1 year agoQuiana
1 year agoLazaro
1 year agoTracey
1 year agoLauran
1 year agoMarva
1 year agoPearline
1 year agoTashia
1 year agoRosina
1 year agoChaya
1 year agoDahlia
1 year agoJamal
1 year agoDevora
1 year agoLavina
1 year ago