A security analyst reviews a SIEM alert related to a suspicious email and wants to verify the authenticity of the message:
SPF = PASS
DKIM = FAIL
DMARC = FAIL
Which of the following did the analyst most likely discover?
Comprehensive and Detailed Step-by-Step The SPF = PASS result confirms the email came from an authorized server, but DKIM = FAIL indicates the message was not properly signed with the expected DomainKeys Identified Mail (DKIM) signature. DMARC = FAIL suggests that because DKIM failed, the overall email authentication failed. This scenario is consistent with a legitimate server sending an unsigned email.
CompTIA CySA+ All-in-One Guide (Chapter 5: Email Analysis)
CompTIA CySA+ Practice Tests (Domain 1.3 Email Authentication)
Bobbye
3 months agoKerry
2 months agoNguyet
2 months agoGarry
2 months agoAdell
2 months agoLeonida
3 months agoChaya
2 months agoQuiana
3 months agoLazaro
3 months agoTracey
3 months agoLauran
3 months agoMarva
3 months agoPearline
3 months agoTashia
3 months agoRosina
2 months agoChaya
2 months agoDahlia
2 months agoJamal
3 months agoDevora
4 months agoLavina
4 months ago