A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:
SPF = PASS
DKIM = FAIL
DMARC = FAIL
Which of the following did the analyst most likely discover?
Comprehensive and Detailed Step-by-Step The SPF = PASS result confirms the email came from an authorized server, but DKIM = FAIL indicates the message was not properly signed with the expected DomainKeys Identified Mail (DKIM) signature. DMARC = FAIL suggests that because DKIM failed, the overall email authentication failed. This scenario is consistent with a legitimate server sending an unsigned email.
CompTIA CySA+ All-in-One Guide (Chapter 5: Email Analysis)
CompTIA CySA+ Practice Tests (Domain 1.3 Email Authentication)
Jettie
4 months agoHerman
4 months agoElly
4 months agoCarmen
4 months agoLyla
4 months agoAngella
5 months agoMabelle
5 months agoElza
5 months agoMyra
5 months agoTorie
6 months agoToshia
6 months agoJaleesa
6 months agoGladys
6 months agoMartina
6 months agoBobbye
12 months agoKerry
10 months agoNguyet
11 months agoGarry
11 months agoAdell
11 months agoLeonida
12 months agoChaya
11 months agoQuiana
11 months agoLazaro
12 months agoTracey
12 months agoLauran
12 months agoMarva
12 months agoPearline
1 year agoTashia
1 year agoRosina
11 months agoChaya
11 months agoDahlia
11 months agoJamal
12 months agoDevora
1 year agoLavina
1 year ago